NA

CVE-2023-24496

Published: 06/07/2023 Updated: 17/07/2023
CVSS v3 Base Score: 4.7 | Impact Score: 2.7 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database.

Vulnerable Product Search on Vulmon Subscribe to Product

milesight milesightvpn 2.0.2