S4E just found a medium-severity finding from http usage detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-46381 Scanner

CVE-2022-46381 scanner - Cross-Site Scripting (XSS) vulnerability in Linear eMerge E3-Series

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-46381
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Linear eMerge E3-Series is a popular access control system that is used in various organizations and institutions. This system is designed to help control and monitor access to a property or facility and to provide a secure environment for employees and visitors.

However, this system has recently been found to be vulnerable to a particular security flaw -- CVE-2022-46381. This vulnerability is caused by the XSS (Cross-Site Scripting) attacks that can occur via the type parameter, such as with the badging/badge_template_v0.php component. Unfortunately, the 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e versions of the Linear eMerge E3-Series are all affected by this vulnerability.

When exploited, the CVE-2022-46381 vulnerability can result in unauthorized access to a monitored facility or property. Attackers can potentially breach the system and expose private information about individuals inside the facility. Compromised security can lead to theft, financial loss, and even physical harm to people inside or outside the facility.

Thankfully, with the pro features of s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets. The platform can help organizations and individuals understand their security risks and take necessary measures to enhance their security posture. It's important to stay informed and invest in the right tools and services to secure your digital assets and protect yourself from cyber threats.

 

REFERENCES

Solution Advice
  • You need to apply related fixes.
  • Sanitize all parameters received as input from the user.
  • Enable CSP (Content Security Policy) with a correct value. CSP aids in the enforcement of security best practices by restricting various actions and limiting the number of origins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.