Loading
Generated remediation guidance and an executive summary. No account required.
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
Use CWE-384, Nortekcontrol vendor hub and Emerge E3 Firmware product page to widen CVE-2022-31798 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-31499, CVE-2018-5439 and CVE-2022-31269 for nearby disclosures in the same product family.