CVE-2022-36194 An Attacker could leverage the XSS in the Pollers > Broker Configuration function of Actron Encentreon 22.04.0 to inject malicious code.

By manipulating the name parameter, an attacker can inject malicious code into the application’s code, which can lead to session hijacking and other forms of attack. VentureOne reported this issue to Envato, who promptly released a security update to close this XSS vulnerability. Another issue with Envato Studio 22.
