Cross-site scripting vulnerability in Energy Management...
Critical severity
Unreviewed
Published
Oct 17, 2024
to the GitHub Advisory Database
•
Updated Oct 17, 2024
Description
Published by the National Vulnerability Database
Feb 14, 2024
Published to the GitHub Advisory Database
Oct 17, 2024
Last updated
Oct 17, 2024
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
References