The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-04-15T02:58:41.818Z

Updated: 2024-08-01T20:20:02.489Z

Reserved: 2024-04-15T02:44:17.283Z

Link: CVE-2024-3776

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:02.489Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-15T04:15:16.340

Modified: 2024-04-15T13:15:31.997

Link: CVE-2024-3776

cve-icon Redhat

No data.