CVE-2019-12460
MEDIUMWebPort 1.19.1 - Cross-Site Scripting via Setup Type Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-12460. PoCs published by Emre ÖVÜNÇ, EmreOvunc.
AI-analyzed exploit summary This is a proof-of-concept for a reflected XSS vulnerability in WebPort 1.19.1. The exploit demonstrates how an attacker can craft a malicious URL to execute arbitrary JavaScript in the context of a victim's browser session.
Description
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
Exploits (2)
This is a proof-of-concept for a reflected XSS vulnerability in WebPort 1.19.1. The exploit demonstrates how an attacker can craft a malicious URL to execute arbitrary JavaScript in the context of a victim's browser session.
The repository provides functional proof-of-concept exploit code for a reflected XSS vulnerability in WebPort v1.19.1. It includes crafted HTTP requests demonstrating the injection of malicious JavaScript via the 'type' parameter in two endpoints.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N