ZeroHour

CVE-2021-40517

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p43
Published
()
Modified
Description

Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.

Vendors
airangel
Products
hsmx-app-25 firmware, hsmx-app-100 firmware, hsmx-app-1000 firmware, hsmx-app-5000 firmware, hsmx-app-20000 firmware
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.