Reflected XSS in Automated Logic WebCTRL and Carrier i-VU Products
CVE-2024-8528
5.4MEDIUM
What is CVE-2024-8528?
A reflected cross-site scripting vulnerability exists in Automated Logic WebCTRL and Carrier i-VU due to improper sanitization of a specific URL GET parameter. This flaw allows an attacker to deliver malicious payloads to unsuspecting users, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
i-Vu Windows 6.0 <= 9.0
WebCtrl Windows 6.0 <= 9.0
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jaryl Low
Thuy D. Nguyen
Cynthia E. Irvine
