PoC Index

CVE-2020-12259

MEDIUM 5.4EPSS 96.2%

rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
96.18% chance of exploitation in the next 30 days, 100th percentile
Nuclei
medium · CWE-79
Published
2020-05-18
Updated
2024-08-04

Nuclei templates (1)

References

Related