Skip to main content

CVE-2023-24709

Description

An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.

NVD
Severity: HIGH
CVE ID: CVE-2023-24709
CVSS Score: 7.5
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Refrence: NVDMITRE

Proof Of Concept

DRAGOWN

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite configurations in the file "login.xml" and cause the login page to crash.

Refrence: GitHub