Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-0193

Опубликовано: 15 янв. 2025
Источник: nvd
EPSS Низкий

Описание

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

EPSS

Процентиль: 53%
0.00297
Низкий

Дефекты

CWE-79

Связанные уязвимости

github
около 1 года назад

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerability to inject malicious scripts that are continuously stored on the device. These scripts are executed when other users access the login page, potentially resulting in unauthorized actions or other impacts, depending on the user's privileges.

CVSS3: 5.1
fstec
около 1 года назад

Уязвимость функции Login Message микропрограммного обеспечения промышленных Ethernet-шлюзов Moxa MGate, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 53%
0.00297
Низкий

Дефекты

CWE-79