{ "id": "CVE-2023-33276", "sourceIdentifier": "cve@mitre.org", "published": "2023-06-30T14:15:09.427", "lastModified": "2023-06-30T15:29:21.147", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a \"404 - Not Found\" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding, it is vulnerable to reflective cross-site scripting (XSS)." } ], "metrics": {}, "references": [ { "url": "https://www.syss.de/en/responsible-disclosure-policy", "source": "cve@mitre.org" }, { "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-016.txt", "source": "cve@mitre.org" } ] }