Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Silent6Trinity

#46343of 56,328
6.1Total CVSS
Vulnerabilities · 1
PT-2024-25996
6.1
2024-05-16
Sunhillo · Sunhillo Sureline · CVE-2024-34582
**Name of the Vulnerable Software and Affected Versions** Sunhillo SureLine versions through 8.10.0 **Description** The issue allows for cgi/usrPasswd.cgi userid change XSS within the Forgot Password feature. This can be exploited through the `/cgi/usrPasswd.cgi` endpoint, specifically targeting the `userid change` parameter. **Recommendations** For Sunhillo SureLine versions through 8.10.0, consider disabling the Forgot Password feature until a patch is available. Restrict access to the `/cgi/usrPasswd.cgi` endpoint to minimize the risk of exploitation. Avoid using the `userid change` parameter in the affected API endpoint until the issue is resolved.