Vulnerability CVE-2022-36266


Published: 2022-08-08

Description:
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.

See advisories in our WLB2 database:
Topic
Author
Date
High
FLIX AX8 1.46.16 Remote Command Execution
Samy Younsi
20.08.2022

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 References:
https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833
https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf

Copyright 2024, cxsecurity.com

 

Back to Top