CVE-2020-27980

Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.
References
Link Resource
https://genexis.eu/product/platinum/ Product Vendor Advisory
https://www.exploit-db.com/exploits/48948 Exploit Third Party Advisory VDB Entry
https://genexis.eu/product/platinum/ Product Vendor Advisory
https://www.exploit-db.com/exploits/48948 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:genexis:platinum-4410_firmware:1.28:*:*:*:*:*:*:*
cpe:2.3:h:genexis:platinum-4410:v2:*:*:*:*:*:*:*

History

21 Nov 2024, 05:22

Type Values Removed Values Added
References () https://genexis.eu/product/platinum/ - Product, Vendor Advisory () https://genexis.eu/product/platinum/ - Product, Vendor Advisory
References () https://www.exploit-db.com/exploits/48948 - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/48948 - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2020-10-28 19:15

Updated : 2024-11-21 05:22


NVD link : CVE-2020-27980

Mitre link : CVE-2020-27980

CVE.ORG link : CVE-2020-27980


JSON object : View

Products Affected

genexis

  • platinum-4410
  • platinum-4410_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')