PT-2022-16776 · Intelbras · Intelbras Ata 200
Leonardobg
·
Published
2022-08-15
·
Updated
2022-10-26
·
CVE-2022-24654
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
INTELBRAS ATA 200 Firmware version 74.19.10.21
Description
The issue is an authenticated stored cross-site scripting (XSS) vulnerability in the "Field Server Address" field. This allows attackers to inject JavaScript code through a crafted payload.
Recommendations
For INTELBRAS ATA 200 Firmware version 74.19.10.21, consider disabling the "Field Server Address" field until a patch is available to prevent exploitation. Restrict access to this field to minimize the risk of injection of malicious JavaScript code.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intelbras Ata 200