FS S3150-8T2F Switch Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in the FS Inc S3150-8T2F switch, prior to version S3150-8T2F_2.2.0D_135103. The issue resides in the Time Range Configuration feature of the administration interface, where the 'Time Range Name' field does not properly sanitize input. This allows an attacker to inject malicious JavaScript, which is executed in the browser of any user, including administrators, who accesses the affected page.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
