Back

MEDIUM

XSS Vulnerability in GigaVue-FM

Published Mar 10, 2023

Description

The help page in GigaVUE-FM, when using GigaVUE-OS software version 5.0 202, does not require an authenticated user. An attacker could enforce a user into inserting malicious JavaScript code into the URI, that could lead to a Reflected Cross site Scripting.

Affected products

Remediation

Vendor solution

It is recommended to update to the latest available version of GigaVUE-OS.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Mar 10, 2023
Updated Feb 27, 2025
Reserved Feb 8, 2023
CISA Vulnrichment
Updated Feb 27, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published Mar 10, 2023
Updated Feb 27, 2025
Exploited since n/a
EUVD-2023-12764