Skip to content

Instantly share code, notes, and snippets.

View 9thplayer's full-sized avatar
😎
Dreaming and working towards becoming l33t!

Shekhar 9thplayer

😎
Dreaming and working towards becoming l33t!
  • Ottawa
View GitHub Profile
@9thplayer
9thplayer / gist:df042fe48c314dbc1afad80ffed8387d
Created February 19, 2020 03:49
Hitron Router - CODA - 4582U - 7.1.1.30 - Stored XSS Vulnerability
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the > Wireless > Access Control > Add Managed Device screen.
Impact:
Script can be stored in Database and execute every time when users visits it. If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user.
Amongst other things, the attacker can:
1) Perform any action within the application that the user can perform.
2) View any information that the user is able to view.
3) Modify any information that the user is able to modify.
4) Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.