Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://digisol.com | vendor advisory |
https://github.com/the-girl-who-lived/CVE-2020-35262 | third party advisory exploit |
https://youtu.be/E5wEzf-gkOE | third party advisory exploit |