QID 730220

Date Published: 2021-10-11

QID 730220: Advantech R-SeeNet device_graph_page.php Multiple Vulnerabilities

Affected products:
Advantech R-SeeNet v2.4.12 (20.10.2020)
Multiple cross-site scripting vulnerabilities exist in the device_graph_page.php script

QID Detection Logic (Authenticated)
QID sends specifically crafted HTTP GET request to device_graph_page.php and matches the vulnerable response

An attacker can provide these crafted URLs to trigger the vulnerabilities.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Update to the latest version of Advantech R-SeeNet.
    Refer to Advantech R-SeeNet for information on this.

    CVEs related to QID 730220

    Software Advisories
    Advisory ID Software Component Link