The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-7730-584e3-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-04-15T02:58:41.818Z
Updated: 2024-08-01T20:20:02.489Z
Reserved: 2024-04-15T02:44:17.283Z
Link: CVE-2024-3776
Vulnrichment
Updated: 2024-08-01T20:20:02.489Z
NVD
Status : Awaiting Analysis
Published: 2024-04-15T04:15:16.340
Modified: 2024-04-15T13:15:31.997
Link: CVE-2024-3776
Redhat
No data.