Vulnerability Description
Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- http://innovaphone.com
- http://mypbx.com
- https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Firmwar
- http://innovaphone.com
- http://mypbx.com
- https://wiki.innovaphone.com/index.php?title=Reference14r1:Release_Notes_Firmwar
FAQ
What is CVE-2024-28722?
CVE-2024-28722 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
How severe is CVE-2024-28722?
CVE-2024-28722 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28722?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.