cve/2020/CVE-2020-21987.md

21 lines
956 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-21987](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21987)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session.
### POC
#### Reference
- https://www.exploit-db.com/exploits/47806
2024-06-09 00:33:16 +00:00
- https://www.exploit-db.com/exploits/47806
2024-05-25 21:48:12 +02:00
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5556.php
2024-06-09 00:33:16 +00:00
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5556.php
2024-05-25 21:48:12 +02:00
#### Github
No PoCs found on GitHub currently.