Reflected XSS in Automated Logic WebCTRL and Carrier i-VU Products
CVE-2024-8528

5.4MEDIUM

Key Information:

Vendor
CVE Published:
19 November 2025

What is CVE-2024-8528?

A reflected cross-site scripting vulnerability exists in Automated Logic WebCTRL and Carrier i-VU due to improper sanitization of a specific URL GET parameter. This flaw allows an attacker to deliver malicious payloads to unsuspecting users, potentially leading to unauthorized actions or data exposure.

Affected Version(s)

i-Vu Windows 6.0 <= 9.0

WebCtrl Windows 6.0 <= 9.0

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaryl Low
Thuy D. Nguyen
Cynthia E. Irvine
.
CVE-2024-8528 : Reflected XSS in Automated Logic WebCTRL and Carrier i-VU Products