AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-2035

MEDIUM · CVSS 6.1 EPSS 0.72%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-2035
Severity
MEDIUM
CVSS
6.1
EPSS
0.72%

Original NVD Description

A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.