First published: Sun Jun 02 2024(Updated: )
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Milesight DeviceHub | ||
All of | ||
Milesight DeviceHub | =3.0.1-r1 | |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36392 has a high severity rating due to its potential for exploitation through cross-site scripting.
To fix CVE-2024-36392, ensure that input validation and output encoding are properly implemented in the MileSight DeviceHub application.
CVE-2024-36392 is a Cross-site Scripting (XSS) vulnerability, categorized under CWE-79.
CVE-2024-36392 affects the MileSight DeviceHub software.
The risks associated with CVE-2024-36392 include the potential for unauthorized actions on behalf of users and the exposure of sensitive information.