S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-28363 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Reprise License Manager affects v. 14.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-28363
6.1
CVSS

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Reprise License Manager is a software management tool designed to help businesses efficiently track and manage their software licenses. It is commonly used across various industries to manage and protect their software assets. This powerful tool enables administrators to monitor license usage, allocate licenses to users, and manage renewals.

CVE-2022-28363 is a critical vulnerability that has been detected in Reprise License Manager version 14.2. Specifically, it is a reflected cross-site scripting (XSS) vulnerability in the /goform/login_process username parameter via GET. This means that an attacker can inject malicious code into the username field, which the server will then reflect back to the user's browser, thereby executing the code and potentially gaining access to sensitive information.

If exploited, this vulnerability can lead to a range of serious consequences, including unauthorized access to sensitive data, the theft of intellectual property, and even full-scale cyberattacks. The attacker could potentially gain access to critical corporate data, disrupt system operations, and compromise the privacy of both customers and employees.

At s4e.io, we provide powerful security tools and resources designed to help businesses protect their digital assets from threats like CVE-2022-28363. With our pro features, our users can easily and quickly identify vulnerabilities in their systems, detect suspicious activity, and take action to protect their data before it's too late. So if you're looking for a partner to help you secure your software assets, look no further than s4e.io.

 

REFERENCES

Solution Advice

To protect against this vulnerability, administrators of Reprise License Manager installations must take the following precautions:

  • Install the latest software updates provided by the vendor
  • Implement network-level security measures, such as firewalls and intrusion detection systems
  • Educate users on safe browsing practices and the importance of password hygiene
  • Monitor systems for signs of suspicious activity, such as unusual login attempts or data exfiltration
  • Consider implementing two-factor authentication to help prevent unauthorized access to sensitive systems

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.