ZeroHour

CVE-2023-25018

CVSS 3.1
5.4 medium
EPSS
<1%p36
Published
()
Modified
Description

RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can inject JavaScript to perform reflected XSS (Reflected Cross-site scripting) attack.

Vendors
rifartek
Products
iot wall
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.