Cross-Site Scripting in SAMSUNG X7400GX SyncThru Web Service
CVE-2019-7418
6.1MEDIUM
What is CVE-2019-7418?
A cross-site scripting (XSS) vulnerability has been identified in the SAMSUNG X7400GX SyncThru Web Service. This flaw exists in the '/sws/swsAlert.sws' endpoint, where multiple parameters including flag, frame, func, and Nfunc are susceptible to exploitation. Attackers can inject malicious scripts, potentially leading to unauthorized actions or data theft when the affected web service processes these parameters.