Filtered by vendor Rifartek
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-25018 | 1 Rifartek | 1 Iot Wall | 2024-11-21 | N/A | 5.4 MEDIUM |
RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can inject JavaScript to perform reflected XSS (Reflected Cross-site scripting) attack. | |||||
CVE-2023-25017 | 1 Rifartek | 1 Iot Wall | 2024-11-21 | N/A | 8.1 HIGH |
RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform specific privileged function to access and modify all sensitive data. |