---
id: CVE-2022-50787
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site
  Scripting
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored
  cross-site scripting vulnerability in the username parameter that allows
  attackers to inject malicious scripts. Attackers can exploit the unvalidated
  username …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-79
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-01-02T19:57:56.427444Z'
exploitAvailable: true
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:07.118Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50787'
references:
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5731.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5731)
  - url: >-
      https://packetstormsecurity.com/files/170258/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Persistent-Cross-Site-Scripting.html
    label: Packet Storm Security Exploit Details
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247920'
    label: IBM X-Force Vulnerability Exchange Entry
  - url: 'https://www.sound4.com/'
    label: SOUND4 Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-stored-cross-site-scripting
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated
      Stored Cross-Site Scripting
tags:
  - cve.org
  - exploit-available
epss: 0.00442
epssPercentile: 0.36054
ingestedAt: '2026-10-01T19:58:57.580Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions without authentication.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
