CVE-2020-7236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
19/01/2020
Last modified:
23/01/2020

Description

UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:uhp:uhp-100_firmware:3.4.1.15:*:*:*:*:*:*:*
cpe:2.3:o:uhp:uhp-100_firmware:3.4.2.4:*:*:*:*:*:*:*
cpe:2.3:o:uhp:uhp-100_firmware:3.4.3:*:*:*:*:*:*:*
cpe:2.3:h:uhp:uhp-100:-:*:*:*:*:*:*:*