CVE-2018-19391

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/03/2019
Last modified:
15/03/2019

Description

Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cobham:satcom_sailor_250_firmware:*:*:*:*:*:*:*:* 1.25 (excluding)
cpe:2.3:h:cobham:satcom_sailor_250:-:*:*:*:*:*:*:*
cpe:2.3:o:cobham:satcom_sailor_500_firmware:*:*:*:*:*:*:*:* 1.25 (excluding)
cpe:2.3:h:cobham:satcom_sailor_500:-:*:*:*:*:*:*:*