Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 8.0
affected
Default status
unaffected
Any version before 8.0
affected
Description
The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser .
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 8.0
Any version before 8.0
Credits
Steve Knabe from Praetorian
Inacio Santos
References
www.corporate.carrier.com/...-security/advisories-resources/