PT-2025-5686 · Sensaphone · Sensaphone Web600

CVE-2024-55040

·

Publicado

2025-02-05

·

Atualizado

2025-07-21

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Sensaphone Web600 (affected versions not specified)
Description: The issue concerns stored cross-site scripting (XSS) in the system's Setup, Profile, and Zone options. This means that an attacker could potentially inject malicious code into these areas, which would then be executed by the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-55040

Produtos afetados

Sensaphone Web600