A stored cross-site scripting (XSS) vulnerability exists...
Moderate severity
Unreviewed
Published
Oct 11, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Oct 11, 2023
Published to the GitHub Advisory Database
Oct 11, 2023
Last updated
Apr 4, 2024
A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An attacker can make an authenticated HTTP request to trigger this vulnerability.
References