CVE-2023-5880

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/01/2024
Last modified:
27/08/2024

Description

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users&amp;#39; web browser. <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:geniecompany:aladdin_connect_garage_door_opener_firmware:*:*:*:*:*:*:*:* 14.1.1 (including)
cpe:2.3:h:geniecompany:aladdin_connect_garage_door_opener:-:*:*:*:*:*:*:*