CVEs Blog | G5 Cyber Security

CVE-2020-22158 – MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to mul

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the “path” or “Services+ID” parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the “name” parameter with the malicious code.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22158

Reference (s):

Exit mobile version