CVE-2009-0699

LOW
CVSS v3
3.5CVSS v2
0.44% EPSS (exploit probability)
CWE-79CWE

Description

Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
Ubiquiti Ubiquiti EdgeRouter 4 Unpatched

External references