6.1
CVSSv3

CVE-2023-28648

Published: 28/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

Vulnerable Product Search on Vulmon Subscribe to Product

propumpservice osprey_pump_controller_firmware 1.01