CVE-2017-17737
MEDIUMBrightSign 4K242 Firmware < 6.2.63 - Cross-Site Scripting via REF Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17737. PoCs published by Information Paradox.
AI-analyzed exploit summary The writeup describes multiple vulnerabilities in BrightSign Digital Signage (Firmware 6.2.63 and below), including XSS, directory traversal, and unauthenticated file upload/modification. These can be combined to compromise the device and end users.
Description
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.
Exploits (1)
The writeup describes multiple vulnerabilities in BrightSign Digital Signage (Firmware 6.2.63 and below), including XSS, directory traversal, and unauthenticated file upload/modification. These can be combined to compromise the device and end users.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N