QID 730219

Date Published: 2021-10-11

QID 730219: Advantech R-SeeNet ssh_form.php Reflected Cross-Site Scripting (XSS) Vulnerability

AFFECTED PRODUCTS
XSS vulnerability exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).

QID Detection Logic (Authenticated)
QID sends specifically crafted HTTP GET request to ssh_form.php and matches the vulnerable response

A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Update to the latest version of Advantech R-SeeNet.
    Refer to Advantech R-SeeNet for information on this.

    CVEs related to QID 730219

    Software Advisories
    Advisory ID Software Component Link