Vulnerability Description
Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
Related Weaknesses (CWE)
References
- https://github.com/LinkItONEDevGroup/LASS/commits/master/
- https://www.vulncheck.com/advisories/linkit-one-location-aware-sensor-system-las
FAQ
What is CVE-2026-32843?
CVE-2026-32843 is a documented vulnerability. Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbi...
How severe is CVE-2026-32843?
CVSS scoring is not yet available for CVE-2026-32843. Check NVD for updates.
Is there a patch for CVE-2026-32843?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.