When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-08-27T15:30:42.784Z
Reserved: 2023-10-31T13:56:12.783Z
Link: CVE-2023-5880
Updated: 2024-08-02T08:14:24.315Z
Status : Modified
Published: 2024-01-03T20:15:21.833
Modified: 2024-11-21T08:42:41.887
Link: CVE-2023-5880
No data.
OpenCVE Enrichment
No data.
Weaknesses