Description
A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote attackers to perform arbitrary Javascript execution through entering a crafted payload into the 'Model' field then saving.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18039 | A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote attackers to perform arbitrary Javascript execution through entering a crafted payload into the 'Model' field then saving. |
References
| Link | Providers |
|---|---|
| https://stark0de.com/2020/08/27/pwning-rconfig-part-one.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:33:05.523Z
Reserved: 2020-09-14T00:00:00.000Z
Link: CVE-2020-25352
No data.
Status : Modified
Published: 2021-08-20T19:15:08.270
Modified: 2024-11-21T05:17:53.530
Link: CVE-2020-25352
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD