漏洞描述
Jeedom through 4.0.38 contains a cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
sysdream.comhttps://sysdream.com/news/lab/2020-08-05-cve-2020-9036-jeedom-xss-leading-to-remote-code-execution/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-9036↗github.comhttps://github.com/ARPSyndicate/cvemon↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/my3ker/my3ker-cve-workshop↗