CVE Database
/

CVE-2023-5880

Back to search

CVE-2023-5880

Published: Jan 3, 2024

Modified: Aug 27, 2024

PUBLISHED

Description

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser. 

VendorProductVersions

The Genie Company

Aladdin Connect (Retrofit-Kit)

affected
0 - <= <=14.1.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now