Required CVE Record Information
Description
A vulnerability classified as problematic was found in Zebra ZTC GK420d 1.0. This vulnerability affects unknown code of the file /settings of the component Alert Setup Page. The manipulation of the argument Address leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258868. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 3 Total
Score | Severity | Version | Vector String |
---|---|---|---|
2.4 | LOW | 3.1 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
2.4 | LOW | 3.0 | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
3.3 | — | 2.0 | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Credits
- Strik3r (VulDB User) reporter
References 4 Total
- vuldb.com: VDB-258868 | Zebra ZTC GK420d Alert Setup Page settings cross site scripting vdb-entrytechnical-description
- vuldb.com: VDB-258868 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- vuldb.com: Submit #303446 | Zebra Technologies ZTC GK420d 1.0 Stored Cross Site Scripting third-party-advisory
- https://github.com/strik3r0x1/Vulns/blob/main/ZTC_GK420d-SXSS.md exploit
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- vuldb.com: VDB-258868 | Zebra ZTC GK420d Alert Setup Page settings cross site scripting vdb-entrytechnical-descriptionx_transferred
- vuldb.com: VDB-258868 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-requiredx_transferred
- vuldb.com: Submit #303446 | Zebra Technologies ZTC GK420d 1.0 Stored Cross Site Scripting third-party-advisoryx_transferred
- https://github.com/strik3r0x1/Vulns/blob/main/ZTC_GK420d-SXSS.md exploitx_transferred