PT-2015-5892 · Hotspot Express · Hotspot Express Hotex Billing Manager
Bhadresh Patel
·
Published
2015-04-14
·
Updated
2018-10-09
·
CVE-2015-2781
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hotspot Express hotEx Billing Manager version 73
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the
reply parameter in the /cgi-bin/hotspotlogin.cgi API endpoint.Recommendations
For Hotspot Express hotEx Billing Manager version 73, consider restricting access to the
/cgi-bin/hotspotlogin.cgi endpoint until a patch is available, and avoid using the reply parameter in this endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotspot Express Hotex Billing Manager