CVE-2020-22158 Information
Feb 14, 2021
cve
Description
MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the \path\ or \Services+ID\ parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS an attacker must modify the \name\ parameter with the malicious code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://sku11army.blogspot.com/2020/02/ericsson-multiple-stored-reflected-xss.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: