Leica Geosystems GR10/GR25/GR30/GR50...

- AV AC AU C I A
发布: 2019-01-07
修订: 2025-04-13

Leica Geosystems GR10/GR25/GR30/GR50 GNSS version 4.30.063 suffers from a stored cross site scripting vulnerability. The issue is triggered via unrestricted file upload while restoring a config file allowing the attacker to upload an html or javascript file that will be stored in /settings/poc.html. This can be exploited to execute arbitrary HTML or JS code in a user's browser session in context of an affected site.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息