First published: Tue Oct 10 2017(Updated: )
A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the hosts array parameter to module/admin_device/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EyesOfNetwork EyesOfNetwork | =5.1-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-15188 is considered high due to the ability of authenticated administrators to inject arbitrary scripts.
To fix CVE-2017-15188, upgrade to a more recent version of EyesOfNetwork that addresses the XSS vulnerability.
CVE-2017-15188 affects authenticated administrators using EyesOfNetwork version 5.1-0.
An attacker can exploit CVE-2017-15188 to execute arbitrary web scripts or HTML within the web interface.
CVE-2017-15188 occurs in the EyesOfNetwork web interface, specifically in the module/admin_device/index.php.