ZeroHour

CVE-2020-12256

PoC
CVSS 3.1
5.4 medium
EPSS
96%p100
Published
()
Modified
Description

rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.

Vendors
rconfig
Products
rconfig
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.