Описание
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.
EPSS
Процентиль: 7%
0.00027
Низкий
9.3 Critical
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 9.3
github
7 месяцев назад
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.
EPSS
Процентиль: 7%
0.00027
Низкий
9.3 Critical
CVSS3
Дефекты
CWE-79