CVE-2020-21987
MEDIUMHomeAutomation 3.3.2 - Stored Cross-Site Scripting via Input Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-21987. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates stored and reflected XSS vulnerabilities in HomeAutomation 3.3.2. The PoC includes a reflected XSS via a crafted URL and a stored XSS via a malicious macro comment field.
Description
HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session.
Exploits (1)
This exploit demonstrates stored and reflected XSS vulnerabilities in HomeAutomation 3.3.2. The PoC includes a reflected XSS via a crafted URL and a stored XSS via a malicious macro comment field.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N