packetstormsecurity.com
http://packetstormsecurity.com/files/164537/Mitsubishi-Electric-INEA-SmartRTU-Cross-Site-Scripting.html CVE-2018-16061
MEDIUM
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2018-16061 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBMitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)ExploitDB exploitby Hamit CİBONot analyzed1 file
References
3drive.google.com
https://drive.google.com/open?id=1DEZQqfpIgcflY2cF6O0y7vtlWYe8Wjjv nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-16061