Vulnerability Description
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Milesight | Ur51 Firmware | < 35.3.0.7 |
| Milesight | Ur51 | - |
| Milesight | Ur52 Firmware | < 35.3.0.7 |
| Milesight | Ur52 | - |
| Milesight | Ur55 Firmware | < 35.3.0.7 |
| Milesight | Ur55 | - |
| Milesight | Ur32L Firmware | < 35.3.0.7 |
| Milesight | Ur32L | - |
| Milesight | Ur32 Firmware | < 35.3.0.7 |
| Milesight | Ur32 | - |
| Milesight | Ur35 Firmware | < 35.3.0.7 |
| Milesight | Ur35 | - |
| Milesight | Ur41 Firmware | < 35.3.0.7 |
| Milesight | Ur41 | - |
Related Weaknesses (CWE)
References
- https://gist.github.com/win3zz/c7eda501edcf5383df32fabe00938d13ExploitThird Party Advisory
- https://gist.github.com/win3zz/c7eda501edcf5383df32fabe00938d13ExploitThird Party Advisory
FAQ
What is CVE-2023-43260?
CVE-2023-43260 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
How severe is CVE-2023-43260?
CVE-2023-43260 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43260?
Check the references section above for vendor advisories and patch information. Affected products include: Milesight Ur51 Firmware, Milesight Ur51, Milesight Ur52 Firmware, Milesight Ur52, Milesight Ur55 Firmware.