Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://drive.google.com/open?id=1X42Rdb_u4YVieXRqs0jOjyJZOb7DCJT6 | third party advisory exploit |
https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11368 | third party advisory exploit |