Логотип exploitDog
bind:CVE-2024-36140
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-36140

Количество 3

Количество 3

nvd логотип

CVE-2024-36140

около 1 года назад

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-w95c-2q6h-h5mp

около 1 года назад

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2024-10326

около 1 года назад

Уязвимость веб-серверов OZW672 и OZW772, связанная с защитой учётных записей пользователей, позволяющая нарушителю выполнить атаки с помощью межсайтовых сценариев (XSS)

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-36140

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-w95c-2q6h-h5mp

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.

CVSS3: 6.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10326

Уязвимость веб-серверов OZW672 и OZW772, связанная с защитой учётных записей пользователей, позволяющая нарушителю выполнить атаки с помощью межсайтовых сценариев (XSS)

CVSS3: 6.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу