PT-2015-5892 · Hotspot Express · Hotspot Express Hotex Billing Manager

Bhadresh Patel

·

Published

2015-04-14

·

Updated

2018-10-09

·

CVE-2015-2781

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hotspot Express hotEx Billing Manager version 73
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the reply parameter in the /cgi-bin/hotspotlogin.cgi API endpoint.
Recommendations For Hotspot Express hotEx Billing Manager version 73, consider restricting access to the /cgi-bin/hotspotlogin.cgi endpoint until a patch is available, and avoid using the reply parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2781

Affected Products

Hotspot Express Hotex Billing Manager