CVE-2023-24496

CVSS V2 None CVSS V3 None
Description
Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database.
Overview
  • CVE ID
  • CVE-2023-24496
  • Assigner
  • talos
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-07-06T14:53:31.258Z
  • Last Modified Date
  • 2023-07-17T18:49:06.317Z
History
Created Old Value New Value Data Type Notes
2024-06-25 07:22:30 Added to TrackCVE