Description
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 5.4
Credits
Alex Williams from Pellera Technologies
References
advcloudfiles.advantech.com/...RITY-ADVISORY----DeviceOn.pdf
docs.deviceon.advantech.com/docs/resource/
www.vulncheck.com/...enticated-stored-xss-via-action-defined