packetstormsecurity.com
http://packetstormsecurity.com/files/152625/JioFi-4G-M2S-1.0.2-Cross-Site-Scripting.html CVE-2019-7438
MEDIUM
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
Record summary
CVE-2019-7438 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJioFi 4G M2S 1.0.2 - 'mask' Cross-Site ScriptingExploitDB exploitby Vikas ChaudharyNot analyzed1 file
References
5gkaim.com
https://gkaim.com/cve-2019-7438-html-vikas-chaudhary gkaim.com
https://gkaim.com/cve-2019-7438-xss-vikas-chaudhary nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-7438 46751exploit
https://www.exploit-db.com/exploits/46751