PT-2017-13880 · Eyesofnetwork · Eyesofnetwork

Published

2017-10-10

·

Updated

2021-02-23

·

CVE-2017-15188

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EyesOfNetwork version 5.1-0
Description A persistent XSS issue in the EyesOfNetwork web interface allows remote authenticated administrators to inject arbitrary web script or HTML via the hosts array parameter to the "module/admin device/index.php" API endpoint.
Recommendations For version 5.1-0, as a temporary workaround, consider restricting access to the "module/admin device/index.php" endpoint until a patch is available. Avoid using the hosts array parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15188

Affected Products

Eyesofnetwork