Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php
Vulnerability Description
Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
LASS 跨站脚本漏洞
Vulnerability Description
LASS是LinkItONEDevGroup开源的一个环境监测传感器网络系统。 LASS f06bd20版本及之前版本存在跨站脚本漏洞,该漏洞源于PM25.php文件存在反射型跨站脚本漏洞,可能导致远程攻击者执行任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A