PoC Index

CVE-2020-12256

MEDIUM 5.4EPSS 95.8%

rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
95.75% chance of exploitation in the next 30 days, 100th percentile
Nuclei
medium · CWE-79
Published
2020-05-18
Updated
2024-08-04

Nuclei templates (1)

References

Related