PT-2024-14124 · Unknown · Universal Passport Rx

Matsumoto Yuuki

·

Published

2024-06-03

·

Updated

2024-07-03

·

CVE-2023-51436

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions UNIVERSAL PASSPORT RX versions 1.0.0 through 1.0.8
Description A cross-site scripting issue exists, which may allow a remote authenticated attacker with administrative privileges to execute an arbitrary script on the user's web browser.
Recommendations For UNIVERSAL PASSPORT RX versions 1.0.0 through 1.0.8, consider disabling administrative access to the web interface until a patch is available. Restrict access to the product's web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-51436

Affected Products

Universal Passport Rx