Description
SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logged_page.php that allows attackers to inject malicious scripts. Attackers can exploit this weakness by sending crafted POST requests to execute arbitrary HTML and script code in a victim's browser session.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
170000
141007
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5518.php
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5518.php (Zero Science Lab Vulnerability Entry)
packetstormsecurity.com/files/152837 (Packet Storm Security Exploit Entry)
cxsecurity.com/issue/WLB-2019050151 (CXSecurity Vulnerability Listing)
exchange.xforce.ibmcloud.com/vulnerabilities/160976 (IBM X-Force Vulnerability Exchange)
www.socatech.com/ (SOCA Vendor Homepage)