Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the remote_subnet field of the database
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1704 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: talos

Published: 2023-07-06T14:53:31.342Z

Updated: 2023-07-17T18:49:06.435Z

Reserved: 2023-01-24T19:20:44.638Z


Link: CVE-2023-24497

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-07-06T15:15:12.037

Modified: 2023-07-17T19:15:09.287


Link: CVE-2023-24497

JSON object: View

cve-icon Redhat Information

No data.

CWE