CVE-2024-34582
MEDIUMSunhillo SureLine <= 8.10.0 - Cross-Site Scripting via Forgot Password Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-34582. PoCs published by silent6trinity.
AI-analyzed exploit summary The repository describes a Reflected XSS vulnerability in Sunhillo Rici5k & Sureline web servers via the `userid_change` parameter in `/cgi/usrPasswd.cgi`. The vulnerability allows malicious JavaScript execution in the context of a user's browser session when exploiting the 'Forgot Password' functionality.
Description
Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.
Exploits (1)
The repository describes a Reflected XSS vulnerability in Sunhillo Rici5k & Sureline web servers via the `userid_change` parameter in `/cgi/usrPasswd.cgi`. The vulnerability allows malicious JavaScript execution in the context of a user's browser session when exploiting the 'Forgot Password' functionality.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N