漏洞描述
The rConfig 3.9.4 is vulnerable to cross-site scripting. The devicemgmnt.php file improperly validates the request coming from the user input. Due to this flaw, An attacker can exploit this vulnerability by crafting arbitrary javascript in `deviceId` GET parameter of devicemgmnt.php resulting in execution of the javascript.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.rconfig.comhttps://www.rconfig.com/downloads/rconfig-3.9.4.zip↗gist.github.comhttps://gist.github.com/farid007/8855031bad0e497264e4879efb5bc9f8↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-12256↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/Elsfa7-110/kenzer-templates↗