packetstormsecurity.com
http://packetstormsecurity.com/files/163343/AKCP-sensorProbe-SPX476-Cross-Site-Scripting.html CVE-2021-35956
MEDIUM
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
Record summary
CVE-2021-35956 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBAKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)ExploitDB exploitby Tyler ButlerNot analyzed1 file
Repository PoCs
GitHubtcbutler320/CVE-2021-35956Repository PoCby tcbutler320Stars: 1Not analyzed1 file
References
5akcp.in.th
http://www.akcp.in.th/downloads/Firmwares/SP480-20210624.zip nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-35956 tbutler.org
https://tbutler.org/2021/06/28/cve-2021-35956 akcp.com
https://www.akcp.com/support-center/customer-login/sensor-probe-firmware-changelog