Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22gj-rr23-9xgc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

EPSS

Процентиль: 41%
0.00185
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
около 5 лет назад

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

EPSS

Процентиль: 41%
0.00185
Низкий