authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38489 | A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker with high privileges to inject malicious HTML or JavaScript code (XSS). |
No history.
Subscriptions
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-08-02T16:10:06.979Z
Reserved: 2023-06-05T12:05:57.451Z
Link: CVE-2023-34412
No data.
Status : Modified
Published: 2023-08-17T14:15:09.700
Modified: 2026-06-17T06:03:35.650
Link: CVE-2023-34412
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD