CVE-2019-7693

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/02/2019
Last modified:
12/02/2019

Description

Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations, the XSS would be on the family.axioscloud.it cloud service; however, the vendor also supports "Sissi in Rete (con server)" for offline operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:axiositalia:registro_elettronico:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:axiositalia:registro_elettronico:7.0.0:*:*:*:*:*:*:*