CVE-2018-5303
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/05/2018
Last modified:
13/06/2018
Description
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the web application is vulnerable to Cross Site Scripting; this vulnerability allows an attacker to send malicious code to another user.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:impinj:r420_rfid_reader_firmware:*:*:*:*:*:*:*:* | 2.2.2 (excluding) | |
| cpe:2.3:h:impinj:r420_rfid_reader:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



