QID 730220
Date Published: 2021-10-11
QID 730220: Advantech R-SeeNet device_graph_page.php Multiple Vulnerabilities
Affected products:
Advantech R-SeeNet v2.4.12 (20.10.2020)
Multiple cross-site scripting vulnerabilities exist in the device_graph_page.php script
QID Detection Logic (Authenticated)
QID sends specifically crafted HTTP GET request to device_graph_page.php and matches the vulnerable response
An attacker can provide these crafted URLs to trigger the vulnerabilities.
Solution
Update to the latest version of Advantech R-SeeNet.
Refer to Advantech R-SeeNet for information on this.
Refer to Advantech R-SeeNet for information on this.
Vendor References
- TALOS-2021-1272 -
talosintelligence.com/vulnerability_reports/TALOS-2021-1272
CVEs related to QID 730220
Software Advisories
| Advisory ID | Software | Component | Link |
|---|