QID 730160

Date Published: 2021-08-19

QID 730160: Advantech R-SeeNet telnet_form.php Reflected XSS vulnerability

AFFECTED PRODUCTS
The following versions of R-SeeNet, a monitoring application, are affected:
Advantech R-SeeNet 2.4.12

QID Detection Logic (Authenticated)
QID sends specifically crafted HTTP GET request to telnet_form.php and matches the vulnerable response

A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Update to the latest version of Advantech R-SeeNet.
    Refer to Advantech R-SeeNet for information on this.

    CVEs related to QID 730160

    Software Advisories
    Advisory ID Software Component Link