PT-2026-6588 · Unknown · P5 Fnip-8X16A+1

Published

2026-02-05

·

Updated

2026-02-05

·

CVE-2020-37148

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11
Description P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 are affected by a stored cross-site scripting issue. Input provided to various GET/POST parameters is not adequately sanitized before being presented back to the user, potentially enabling attackers to inject and execute arbitrary HTML and script code within a user's browser session. This can be achieved by submitting malicious input through the label modification functionality, specifically utilizing the lab4 parameter in the 'config.html' file.
Recommendations Versions 1.0.20 and 1.0.11 should be updated to a newer, secure version.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-37148

Affected Products

P5 Fnip-4Xsh
P5 Fnip-8X16A