CVE-2019-7438
MEDIUMJioFi 4G M2S 1.0.2 - Cross-Site Scripting via mask POST Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-7438. PoCs published by Vikas Chaudhary.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in JioFi 4G M2S routers via the 'mask' parameter in the '/cgi-bin/qcmap_web_cgi' endpoint. The PoC injects a fake login page to deceive users into submitting credentials to an attacker-controlled site.
Description
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in JioFi 4G M2S routers via the 'mask' parameter in the '/cgi-bin/qcmap_web_cgi' endpoint. The PoC injects a fake login page to deceive users into submitting credentials to an attacker-controlled site.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N