Description
A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.
Product status
10.7.0.0 (semver)
10.4.0.0 (semver)
8.12.0.0 (semver)
8.10.0.0 (semver)
References
support.hpe.com/...y?docId=hpesbnw04845en_us&docLocale=en_US