Vulnerability Description
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configuration file upload functionality. Attackers can upload a malicious HTML file to that executes arbitrary JavaScript in a user's browser session when viewed.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/46091
- https://www.leica-geosystems.com
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5503.php
- https://www.exploit-db.com/exploits/46091
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5503.php
FAQ
What is CVE-2018-25131?
CVE-2018-25131 is a vulnerability with a CVSS score of 7.2 (HIGH). Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configuration file upload functionality. Attackers can upload a malicious HTML file to th...
How severe is CVE-2018-25131?
CVE-2018-25131 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25131?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.