CVE-2022-34094 Scanner

Detects 'Cross-Site Scripting' vulnerability in Software Publico Brasileiro i3geo affects version 7.0.5.


CVE-2022-34094 Scanner Detail

The Software Publico Brasileiro i3geo, version 7.0.5, is an innovative geoprocessing tool used extensively by Brazilian public institutions and the global open-source community. It facilitates the integration of mapping services and spatial data analysis into web applications, enhancing public service delivery and environmental management. Developed under the Brazilian Public Software initiative, i3geo aims to foster collaboration and share critical spatial data among users, promoting transparency and efficiency in public administration and spatial planning.

CVE-2022-34094 identifies a medium-severity vulnerability in the i3geo platform, specifically through the request_token.php component. This Cross-Site Scripting (XSS) flaw allows attackers to inject malicious scripts into web pages viewed by other users. Exploitation of this vulnerability can lead to unauthorized actions being performed, access to sensitive information, and manipulation of user sessions.

The XSS vulnerability found in request_token.php of i3geo version 7.0.5 results from inadequate sanitization of user-supplied input. Attackers can exploit this by crafting malicious URLs containing JavaScript code, which is executed in the victim's browser upon visiting. This vulnerability poses a significant security risk, potentially leading to data theft, session hijacking, and other malicious activities.

If exploited, the XSS vulnerability in i3geo could compromise user privacy, security, and trust in the platform. Attackers could manipulate content, steal cookies, or redirect users to phishing sites, leading to further security breaches. Such incidents could undermine the credibility of public services utilizing i3geo, affecting public trust and the integrity of spatial data management.

If exploited, the XSS vulnerability in i3geo could compromise user privacy, security, and trust in the platform. Attackers could manipulate content, steal cookies, or redirect users to phishing sites, leading to further security breaches. Such incidents could undermine the credibility of public services utilizing i3geo, affecting public trust and the integrity of spatial data management.



