Record summary

CVE-2020-12262 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMIntelbras TIP200/TIP200LITE/TIP300 - Cross-Site ScriptingCVSS 5.4

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 are vulnerable to reflected cross-site scripting (XSS) via the page parameter in /cgi-bin/cgiServer.exx, allowing attackers to execute arbitrary JavaScript in the context of the user.

Impact

Authenticated attackers can inject malicious JavaScript through the page parameter, potentially stealing session cookies or performing unauthorized actions on behalf of authenticated users.

Remediation

Update the device firmware to the latest version provided by Intelbras.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2020intelbrastip200tip200litetip300xssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Shodan: title:"Intelbras"
FOFA: title="Intelbras"

Source: ProjectDiscovery

References

4