Loading HuntDB...

HTML Injection on airlink.ubnt.com

Low
U
Ubiquiti Inc.
Submitted None
Reported by ruisilva

Vulnerability Details

Technical details and impact analysis

Code Injection
Hi I found an html injection vulnerability on airlink.ubnt.com Steps to reproduce: First go to: https://airlink.ubnt.com/#/ptp Next go on Save Simulation button and as simulation name put: "><marquee><h1>HTMLINJECTIONHERE</h1></marquee> and save it Now go on Open Simulation button and you will see html being executed :) Your team should fix it Thanks

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Code Injection