NA

CVE-2024-34582

Published: 16/05/2024 Updated: 16/05/2024

Vulnerability Summary

Sunhillo SureLine up to and including 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

Github Repositories

CVE-2024-34582 Affects the latest versions of Mozilla & Chrome Web Browsers, Sunhillo Rici5k & Sureline The most current versions of the Web Servers running on the Sunhillo devices are susceptible to Reflected XSS The vulnerability lies within the userid_change parameter within /cgi/usrPasswdcgi This parameter is copied into the value of an HTML tag when the