Vulnerability Description
Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sensaphone | Web600 Firmware | <= 1.6.5.H |
| Sensaphone | Web600 | - |
Related Weaknesses (CWE)
References
- https://github.com/tcbutler320/Sensaphone-WEB600-XSSThird Party Advisory
- https://sensaphone.com/products/sensaphone-web600-monitoring-systemProduct
- https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-55040Third Party Advisory
FAQ
What is CVE-2024-55040?
CVE-2024-55040 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads...
How severe is CVE-2024-55040?
CVE-2024-55040 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-55040?
Check the references section above for vendor advisories and patch information. Affected products include: Sensaphone Web600 Firmware, Sensaphone Web600.