exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NJohnsoncontrols Exacqvision Web Service
APPJohnsoncontrols≤ 21.03
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
Powiązane podatności
CVE-2021-27664CRITICAL9.8PL ✓ten sam produkt
Nieautoryzowany dostęp do poświadczeń w Johnson Controls exacqVision Web Service
CVE-2024-32862MEDIUM6.8ten sam produkt
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted...
CVE-2024-32864MEDIUM6.4ten sam produkt
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
CVE-2024-32931MEDIUM5.7ten sam produkt
Under certain circumstances the exacqVision Web Service can expose authentication token details within communi...
CVE-2024-32863MEDIUM6.8ten sam produkt
Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSR...