VulnerabilityModified
CVE-2008-4931
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
MEDIUM 4.3EPSS 1.46%
Does this matter?
Lower severity and a low EPSS score (1.46%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- firmchannel/digital signage
- Source
- cve@mitre.org
References
- http://osvdb.org/49564
- http://secunia.com/advisories/32549
- http://securityreason.com/securityalert/4566
- http://www.securityfocus.com/archive/1/498042/100/0/threaded
- http://osvdb.org/49564
- http://secunia.com/advisories/32549
- http://securityreason.com/securityalert/4566
- http://www.securityfocus.com/archive/1/498042/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.