Persistent XSS Vulnerability in Cobham Satcom Sailor 800 and 900 Devices
CVE-2018-19394
4.8MEDIUM
What is CVE-2018-19394?
Cobham Satcom Sailor 800 and 900 devices are vulnerable to a persistent Cross-Site Scripting (XSS) flaw that can be exploited if an attacker gains administrative access. This vulnerability allows the attacker to modify the device's configuration file by inserting malicious XSS payloads into fields like the Satellite name. Once the altered configuration file is restored, it executes the payload, compromising the integrity and security of the device. This poses significant risks, especially in applications where these devices are used.
