vendor:
Osprey Pump Controller
by:
LiquidWorm
9.8
CVSS
CRITICAL
Unauthenticated Reflected XSS
79
CWE
Product Name: Osprey Pump Controller
Affected Version From: Software Build ID 20211018, Production 10/18/2021
Affected Version To: Mirage App: MirageAppManager, Release [1.0.1]
Patch Exists: YES
Related CWE: CVE-2021-27092
CPE: a:propump_and_controls:osprey_pump_controller:1.0.1
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=148468, https://www.infosecmatter.com/nessus-plugin-library/?id=58141, https://www.infosecmatter.com/nessus-plugin-library/?id=35409, https://www.infosecmatter.com/nessus-plugin-library/?id=35421, https://www.infosecmatter.com/nessus-plugin-library/?id=107968
Platforms Tested:
2021
Osprey Pump Controller v1.0.1 – Unauthenticated Reflected XSS
A reflected cross-site scripting (XSS) vulnerability exists in the Osprey Pump Controller v1.0.1 software due to insufficient sanitization of user-supplied input. An attacker can leverage this vulnerability to execute arbitrary HTML and script code in a user's browser session in the context of the affected site.
Mitigation:
ProPump and Controls, Inc. should implement proper input validation and sanitization to prevent malicious code from being executed.