Описание
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Broken Link
- Not ApplicableThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
- ExploitThird Party AdvisoryVDB Entry
- Broken Link
- Not ApplicableThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.38 (включая)
cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.13715
Средний
9 Critical
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 9
github
больше 3 лет назад
Prima Systems FlexAir devices allow Authenticated Stored XSS.
EPSS
Процентиль: 94%
0.13715
Средний
9 Critical
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79