Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf | vendor advisory |
https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf | vendor advisory |
https://jvn.jp/en/vu/JVNVU94591337/ | third party advisory |