Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations, the XSS would be on the family.axioscloud.it cloud service; however, the vendor also supports "Sissi in Rete (con server)" for offline operation.
References
Link Resource
http://storage.axiositalia.com/Quick_Guide/Manuale_Avviamento.pdf Product Vendor Advisory
https://pastebin.com/raw/nQ648Dif Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-10T22:00:00

Updated: 2019-02-10T22:57:01

Reserved: 2019-02-10T00:00:00


Link: CVE-2019-7693

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-02-10T22:29:00.247

Modified: 2019-02-12T20:50:39.223


Link: CVE-2019-7693

JSON object: View

cve-icon Redhat Information

No data.

CWE