vendor:
RTC-1000
by:
Keith Thome
5,4
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: RTC-1000
Affected Version From: <= v2.5.7458
Affected Version To: <= v2.5.7458
Patch Exists: YES
Related CWE: CVE-2017-16819
CPE: h:icontime:rtc-1000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Hardware
2017
Icon Time Systems RTC-1000 (<= v2.5.7458) Universal Time Clocks Stored XSS Vulnerability
The Icon Time Systems RTC-1000 (firmware v2.5.7458 and below) Universal Time Clock device is susceptible to a stored Cross Site Scripting (XSS) vulnerability that facilitates session hijacking. Injecting a session hijacking XSS payload into the ‘First Name’ field of an employee record on the employee.html webpage results in payload execution wherever this employee's first name appears in subsequent webpages. Caveat: To exploit this vulnerability, the attacker does need valid credentials to access the device and those credentials must have permissions to change employee names.
Mitigation:
Vendor released a patch.