Vulnerabilities (CVE)

Filtered by vendor Rifartek Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-25018 1 Rifartek 1 Iot Wall 2023-12-10 N/A 5.4 MEDIUM
RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can inject JavaScript to perform reflected XSS (Reflected Cross-site scripting) attack.
CVE-2023-25017 1 Rifartek 1 Iot Wall 2023-12-10 N/A 8.1 HIGH
RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform specific privileged function to access and modify all sensitive data.