An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.
References
Link Resource
https://www.mogozobo.com/ Third Party Advisory
https://www.mogozobo.com/?p=3593 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-10-28T12:09:14

Updated: 2019-10-28T12:09:30

Reserved: 2019-08-10T00:00:00


Link: CVE-2019-14928

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-10-28T13:15:10.837

Modified: 2019-10-30T17:57:04.663


Link: CVE-2019-14928

JSON object: View

cve-icon Redhat Information

No data.

CWE