Loading HuntDB...

GHSA-7f4j-hqcw-f2vm

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the remote_subnet field of the database

Related CVEs

Key Information

GHSA ID
GHSA-7f4j-hqcw-f2vm
Published
July 6, 2023 3:30 PM
Last Modified
November 4, 2025 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.