Описание
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
Ссылки
- Vendor Advisory
- US Government Resource
- Not Applicable
- Vendor Advisory
- Vendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.0 (исключая)
Одновременно
cpe:2.3:o:sick:tdc-x401gl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:tdc-x401gl:-:*:*:*:*:*:*:*
EPSS
Процентиль: 11%
0.00038
Низкий
3.8 Low
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 3.8
github
24 дня назад
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
EPSS
Процентиль: 11%
0.00038
Низкий
3.8 Low
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-79