ZeroHour

CVE-2024-3776

CVSS 3.1
6.1 medium
EPSS
<1%p34
Published
()
Modified
Description

The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.

Vendors
netvision
Products
airpass
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.