← Back to CVE List

CVE-2023-24496

Published: 2023-07-06T15:15Z
Last Modified: 2024-11-21T07:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name field of the database. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt