The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.information-paradox.net/2017/12/brightsign-multiple-vulnerablities-cve.html | issue tracking third party advisory |
https://www.exploit-db.com/exploits/43364/ | issue tracking exploit vdb entry third party advisory |