First published: Thu Oct 05 2023(Updated: )
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Milesight Ur51 Firmware | <35.3.0.7 | |
Milesight Ur51 | ||
Milesight Ur52 Firmware | <35.3.0.7 | |
Milesight Ur52 | ||
Milesight Ur55 Firmware | <35.3.0.7 | |
Milesight Ur55 | ||
Milesight Ur32l Firmware | <35.3.0.7 | |
Milesight UR32L | ||
Milesight Ur32 Firmware | <35.3.0.7 | |
Milesight Ur32 | ||
Milesight Ur35 Firmware | <35.3.0.7 | |
Milesight Ur35 | ||
Milesight Ur41 Firmware | <35.3.0.7 | |
Milesight Ur41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43260 is a cross-site scripting (XSS) vulnerability discovered in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 via the admin panel.
Milesight UR5X, UR32L, UR32, UR35, UR41 firmware versions up to (but not including) v35.3.0.7 are affected.
The severity of CVE-2023-43260 is medium, with a severity value of 6.1.
To fix CVE-2023-43260, update Milesight UR5X, UR32L, UR32, UR35, UR41 firmware to version v35.3.0.7 or later.
More information about CVE-2023-43260 can be found at the following reference: [LINK]