CVE-2023-43260: XSS
Published Oct 5, 2023
·Updated
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
Affected Software
14 affected components
Milesight Ur51 Firmware<35.3.0.7
Milesight Ur51
Milesight Ur52 Firmware<35.3.0.7
Milesight Ur52
Milesight Ur55 Firmware<35.3.0.7
Milesight Ur55
Milesight Ur32l Firmware<35.3.0.7
Milesight UR32L
Milesight Ur32 Firmware<35.3.0.7
Milesight UR32
Milesight Ur35 Firmware<35.3.0.7
Milesight UR35
Milesight Ur41 Firmware<35.3.0.7
Milesight UR41
Event History
Oct 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-43260?
CVE-2023-43260 is a cross-site scripting (XSS) vulnerability discovered in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 via the admin panel.
2
Which software versions are affected by CVE-2023-43260?
Milesight UR5X, UR32L, UR32, UR35, UR41 firmware versions up to (but not including) v35.3.0.7 are affected.
3
What is the severity of CVE-2023-43260?
The severity of CVE-2023-43260 is medium, with a severity value of 6.1.
4
How can I fix CVE-2023-43260?
To fix CVE-2023-43260, update Milesight UR5X, UR32L, UR32, UR35, UR41 firmware to version v35.3.0.7 or later.
5
Where can I find more information about CVE-2023-43260?
More information about CVE-2023-43260 can be found at the following reference: [LINK]