CVE-2019-14928: XSS
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.
Other sources
An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-14928.
What is the severity of CVE-2019-14928?
CVE-2019-14928 has a severity score of 5.4 (medium).
Which devices are affected by CVE-2019-14928?
Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0 are affected by CVE-2019-14928.
What type of vulnerability is CVE-2019-14928?
CVE-2019-14928 is a stored cross-site scripting (XSS) vulnerability.
How can an attacker exploit CVE-2019-14928?
An attacker can exploit CVE-2019-14928 by injecting malicious code into the application through stored XSS vulnerabilities.