An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://my.xfinity.com/vulnerabilityreport | not applicable |
https://pensecure.medium.com/cve-2022-45938-f4c0d441da6f | exploit press/media coverage |