First published: Sat Feb 09 2019(Updated: )
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Enphase Envoy Firmware | >=3.0.0<=3.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7677 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability.
To mitigate CVE-2019-7677, ensure that your Enphase Envoy software is updated to a version beyond 3.9.0.
Exploitation of CVE-2019-7677 can lead to unauthorized access to user information through a malicious script.
CVE-2019-7677 affects Enphase Envoy versions from 3.0.0 to 3.9.0.
CVE-2019-7677 occurs via an improper handling of the profileName parameter in the /home URI on TCP port 8888.