Back to search
CVE-2021-35956
Published: Jun 30, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.akcp.in.th/downloads/Firmwares/SP480-20210624.zip
x_refsource_MISC
https://tbutler.org/2021/06/28/cve-2021-35956
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now