Digi · Digi Anywhereusb · CVE-2019-18859
Name of the Vulnerable Software and Affected Versions:
Digi AnywhereUSB version 14
Description:
The issue allows for cross-site scripting (XSS) via a link for the Digi Page.
Recommendations:
For Digi AnywhereUSB version 14, update to a version that includes a fix for this issue, or as a temporary workaround, consider restricting access to links for the Digi Page to minimize the risk of exploitation.