CVE-2024-26367

Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.
Configurations

No configuration.

History

21 Nov 2024, 09:02

Type Values Removed Values Added
References () http://cc.com - () http://cc.com -
References () http://evertz.com - () http://evertz.com -
References () https://wiki.notveg.ninja/blog/CVE-2024-26367/ - () https://wiki.notveg.ninja/blog/CVE-2024-26367/ -

06 Nov 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) Vulnerabilidad de Cross Site Scripting en Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 permite que un atacante remoto ejecute código arbitrario a través de un payload manipulado para los parámetros de inicio de sesión.
CWE CWE-79

14 May 2024, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:16

Updated : 2024-11-21 09:02


NVD link : CVE-2024-26367

Mitre link : CVE-2024-26367

CVE.ORG link : CVE-2024-26367


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')