Beveiligingsadvies

CVE-2023-24497

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-07-06 14:53:31
Laatst bijgewerkt 2025-11-04 19:14:42
Toegewezen door talos
CVSS-score 4.7
Status PUBLISHED

Beschrijving

Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the remote_subnet field of the database