Description
COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5660.php (Zero Science Lab Disclosure (ZSL-2021-5660))
packetstormsecurity.com/files/163834 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/207578 (IBM X-Force Vulnerability Exchange)
cxsecurity.com/issue/WLB-2021080063 (CXSecurity Vulnerability Database Entry)
www.commax.com/ (Vendor Homepage)
www.vulncheck.com/...tem-reflected-xss-via-cookie-parameters (VulnCheck Advisory: COMMAX Biometric Access Control System 1.0.0 Reflected XSS via Cookie Parameters)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.