PT-2020-16886 · Genexis · Genexis Platinum-4410

Published

2020-10-28

·

Updated

2020-11-04

·

CVE-2020-27980

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Genexis Platinum-4410 P4410-V2-1.28
Description The issue allows stored XSS in the WLAN SSID parameter. This could enable an attacker to perform malicious actions, affecting all privileged users through an XSS popup.
Recommendations For Genexis Platinum-4410 P4410-V2-1.28, avoid using the WLAN SSID parameter until the issue is resolved. As a temporary workaround, consider restricting access to the WLAN configuration to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27980

Affected Products

Genexis Platinum-4410