Web Port 1.19.1 allows XSS via the /access/setup type parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/EmreOvunc/WebPort-v1.19.1-Reflected-XSS/ | third party advisory exploit |
https://emreovunc.com/blog/en/WebPort-Reflected-XSS-01.png | third party advisory exploit |
http://packetstormsecurity.com/files/158174/WebPort-1.19.1-Cross-Site-Scripting.html |