HTML Injection on airlink.ubnt.com
Low
U
Ubiquiti Inc.
Submitted None
Actions:
Reported by
ruisilva
Vulnerability Details
Technical details and impact analysis
Hi
I found an html injection vulnerability on airlink.ubnt.com
Steps to reproduce:
First go to: https://airlink.ubnt.com/#/ptp
Next go on Save Simulation button and as simulation name put: "><marquee><h1>HTMLINJECTIONHERE</h1></marquee> and save it
Now go on Open Simulation button and you will see html being executed :)
Your team should fix it
Thanks
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Code Injection