CVE-2020-12259
MEDIUM 5.4EPSS 96.2%
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.
- CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N - EPSS
- 96.18% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- medium · CWE-79
- Published
- 2020-05-18
- Updated
- 2024-08-04