PT-2018-12789 · Samsung · Samsung Syncthru Web Service
Publicado
2018-08-03
·
Atualizado
2018-09-27
·
CVE-2018-14904
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Syncthru Web Service version V4.05.61
Description
The issue concerns multiple unauthenticated XSS attacks. These attacks can be executed on several parameters, such as
ruiFw pid.Recommendations
For Samsung Syncthru Web Service version V4.05.61, consider restricting access to the vulnerable parameters until a patch is available. As a temporary workaround, avoid using the parameter
ruiFw pid in the affected API endpoints.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Samsung Syncthru Web Service