CVE-2020-22158

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/09/2020
Last modified:
12/11/2020

Description

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mediakind:rx8200_firmware:5.13.3:*:*:*:*:*:*:*
cpe:2.3:h:mediakind:rx8200:-:*:*:*:*:*:*:*