---
cve: "CVE-2020-22158"
severity: "LOW"
cvss: 3.1
epss: "66%"
vendor: "n/a"
kev: false
exploited: false
published: "2020-09-14 16:15:11"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T14:58:16+02:00"
---

# CVE-2020-22158

> 3.1 LOW

## Beschreibung

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

## Referenzen

- <https://sku11army.blogspot.com/2020/02/ericsson-multiple-stored-reflected-xss.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-22158) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
