CVE-2020-24061

Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies via a crafted script
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kasdanet:kw5515_firmware:4.3.1.0:*:*:*:*:*:*:*
cpe:2.3:h:kasdanet:kw5515:-:*:*:*:*:*:*:*

History

13 Sep 2024, 16:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 4.3
References () https://github.com/0xadik/CVEs/tree/main/CVE-2020-24061 - () https://github.com/0xadik/CVEs/tree/main/CVE-2020-24061 - Third Party Advisory
References () https://medium.com/%40sadikul.islam/kasda-kw5515-cross-site-scripting-html-injection-e6cb9f65ae89?sk=5e1ea8e1cba8dbeaff7f9cd710808354 - () https://medium.com/%40sadikul.islam/kasda-kw5515-cross-site-scripting-html-injection-e6cb9f65ae89?sk=5e1ea8e1cba8dbeaff7f9cd710808354 - Exploit
CPE cpe:2.3:o:kasdanet:kw5515_firmware:4.3.1.0:*:*:*:*:*:*:*
cpe:2.3:h:kasdanet:kw5515:-:*:*:*:*:*:*:*
First Time Kasdanet kw5515
Kasdanet kw5515 Firmware
Kasdanet
Summary
  • (es) Vulnerabilidad de Cross-site Scripting (XSS) en el menú de Firewall del Panel de control en KASDA KW5515 versión 4.3.1.0, permite a atacantes ejecutar código arbitrario y robar cookies a través de un script manipulado específicamente

12 Sep 2024, 18:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

12 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 18:15

Updated : 2024-09-13 16:05


NVD link : CVE-2020-24061

Mitre link : CVE-2020-24061

CVE.ORG link : CVE-2020-24061


JSON object : View

Products Affected

kasdanet

  • kw5515_firmware
  • kw5515
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')