Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m56g-xx45-238c

Опубликовано: 15 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.2

Описание

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

EPSS

Процентиль: 53%
0.00297
Низкий

5.2 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
около 1 года назад

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

CVSS3: 5.1
fstec
около 1 года назад

Уязвимость функции Login Message микропрограммного обеспечения промышленных Ethernet-шлюзов Moxa MGate, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 53%
0.00297
Низкий

5.2 Medium

CVSS4

Дефекты

CWE-79