First published: Thu Sep 28 2023(Updated: )
There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When HTML files are allowed, XSS payload can be injected into the uploaded file.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Generex Cs141 Firmware | <2.06 | |
Generex CS141 |
This vulnerability, has been fixed by Generex team in CS141 version 2.12, released on December 2022.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-47187.
The severity of CVE-2022-47187 is medium, with a CVSS score of 6.1.
The affected software is Generex CS141 firmware versions up to 2.06.
CVE-2022-47187 is an XSS vulnerability that occurs when a file with HTML content is uploaded to the Generex CS141 web application.
To fix CVE-2022-47187, you should upgrade your Generex CS141 firmware to version 2.06 or above.