Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
References
Link | Resource |
---|---|
https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit_26.html | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-17T03:03:02
Updated: 2020-02-17T03:03:02
Reserved: 2020-02-17T00:00:00
Link: CVE-2020-9025
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-17T04:15:11.123
Modified: 2020-02-19T17:10:20.360
Link: CVE-2020-9025
JSON object: View
Redhat Information
No data.
CWE