Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: talos
Published: 2023-07-06T14:53:31.258Z
Updated: 2024-10-28T15:24:25.399Z
Reserved: 2023-01-24T19:20:44.636Z
Link: CVE-2023-24496
Vulnrichment
Updated: 2024-08-02T10:56:04.283Z
NVD
Status : Modified
Published: 2023-07-06T15:15:11.953
Modified: 2023-07-17T19:15:09.200
Link: CVE-2023-24496
Redhat
No data.