Beveiligingsadvies

CVE-2020-22158

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-09-14 15:23:51
Laatst bijgewerkt 2024-08-04 14:51:10
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.