XSS Vulnerability in Domoticz Smart Home System
CVE-2019-15480

5.4MEDIUM

Key Information:

Vendor

Domoticz

Status
Vendor
CVE Published:
23 August 2019

What is CVE-2019-15480?

The vulnerability in Domoticz version 4.10717 allows attackers to exploit an XSS flaw through the 'item.Name' parameter. This can potentially enable unauthorized actions by injecting malicious scripts into the application. The issue underscores the importance of secure coding practices in home automation solutions to safeguard against such attacks. For further details, visit the project's GitHub issue and pull request discussions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.