CVE-2020-12262
Intelbras TIP200/TIP200LITE/TIP300 - Cross-Site Scripting
Record summary
CVE-2020-12262 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMIntelbras TIP200/TIP200LITE/TIP300 - Cross-Site ScriptingCVSS 5.4
Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 are vulnerable to reflected cross-site scripting (XSS) via the page parameter in /cgi-bin/cgiServer.exx, allowing attackers to execute arbitrary JavaScript in the context of the user.
Impact
Authenticated attackers can inject malicious JavaScript through the page parameter, potentially stealing session cookies or performing unauthorized actions on behalf of authenticated users.
Remediation
Update the device firmware to the latest version provided by Intelbras.
Source: ProjectDiscovery