CVE Published: 07/02/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: talos |
Vendor: Moxa |
Product: SDS-3008 Series Industrial Ethernet Switch Status : PUBLISHED
CVE-2022-41313 Description
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact"