← Back to CVE List

CVE-2022-22999

Published: 2022-07-25T19:15Z
Last Modified: 2024-11-21T06:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may be possible to gain control over the authenticated session, steal data, modify settings, or redirect the user to malicious websites. The scope of impact can extend to other components. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt