Cross-Site Scripting Vulnerability in Moxa AWK-3121 Devices
CVE-2018-10692
6.1MEDIUM
What is CVE-2018-10692?
A security flaw has been identified in Moxa AWK-3121 1.14 devices where the session cookie named 'Password508' is missing the HttpOnly flag. This absence allows an attacker, capable of executing a cross-site scripting (XSS) attack, to easily access and steal the session cookie, potentially compromising user sessions and sensitive data.