CVE Published: 08/01/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: icscert |
Vendor: n/a |
Product: Innokas Yhtymä Oy Vital Signs Monitor VC150 Status : PUBLISHED
CVE-2020-27262 Description
Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability exists in the affected products that allow an attacker to inject arbitrary web script or HTML via the filename parameter to multiple update endpoints of the administrative web interface.