rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-18T13:00:17

Updated: 2020-05-18T13:00:17

Reserved: 2020-04-26T00:00:00


Link: CVE-2020-12259

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-18T13:15:10.893

Modified: 2020-05-18T20:40:41.353


Link: CVE-2020-12259

JSON object: View

cve-icon Redhat Information

No data.

CWE