3.5
CVSSv2

CVE-2019-7671

Published: 05/06/2019 Updated: 25/10/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an malicious user to execute arbitrary code in a user’s browser session in context of an affected site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

primasystems flexair

Exploits

# Exploit Title: Prima Access Control 2335 - 'HwName' Persistent Cross-Site Scripting # Google Dork: NA # Date: 2019-11-11 # Exploit Author: LiquidWorm # Vendor Homepage: wwwcomputrolscom/capabilities-cbas-web/ # Software Link: wwwcomputrolscom/building-automation-software/ # Version: 2335 # Tested on: NA # CVE : CVE-2019-76 ...
Prima Access Control version 2335 suffers from a persistent cross site scripting vulnerability ...