PT-2023-7387 · Unknown · Osprey Pump Controller

CVE-2023-28648

·

Publicado

2023-03-28

·

Atualizado

2023-04-05

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Osprey Pump Controller version 1.01
Description The issue exists due to inadequate protection of the web page structure, allowing a remote attacker to execute arbitrary code. Specifically, inputs passed to a GET parameter are not properly sanitized before being returned to the user, which can be exploited to execute arbitrary HTML/JS code in a user's browser session.
Recommendations For Osprey Pump Controller version 1.01, ensure that inputs passed to GET parameters are properly sanitized to prevent exploitation. As a temporary workaround, consider restricting access to the affected site or disabling the execution of HTML/JS code in the user's browser session until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08419
CVE-2023-28648

Produtos afetados

Osprey Pump Controller