CVE-2018-16061: XSS
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATHINFO to login.php.
Other sources
Mitsubishi Electric SmartRTU devices allow XSS via the username parameter or PATHINFO to login.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16061?
CVE-2018-16061 is a vulnerability that allows XSS (Cross-Site Scripting) attacks in Mitsubishi Electric SmartRTU devices via the username parameter or PATH_INFO to login.php.
What is the severity of CVE-2018-16061?
The severity of CVE-2018-16061 is medium with a CVSS score of 6.1.
How can an XSS attack be performed using CVE-2018-16061?
An XSS attack can be performed by exploiting the username parameter or PATH_INFO to login.php in Mitsubishi Electric SmartRTU devices.
Is there a fix available for CVE-2018-16061?
There is no specific information available about a fix for CVE-2018-16061. It is recommended to contact the vendor for further guidance.
Where can I find more information about CVE-2018-16061?
More information about CVE-2018-16061 can be found at the following references: [Link 1](http://packetstormsecurity.com/files/164537/Mitsubishi-Electric-INEA-SmartRTU-Cross-Site-Scripting.html), [Link 2](https://drive.google.com/open?id=1DEZQqfpIgcflY2cF6O0y7vtlWYe8Wjjv).