FLIR AX8 prod.php cross site scripting

CVE Details

Basic Information

Title FLIR AX8 prod.php cross site scripting
Type cve
Published 2025-05-24T15:31:04.412Z
Last Seen

CVSS Information

Base Score 0.0 ()
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A cross-site scripting (XSS) vulnerability exists in FLIR AX8 versions up to 1.46.16. The vulnerability is located in the /prod.php file and can be exploited by manipulating the ‘cmd’ argument. The attack can be initiated remotely, and the vulnerability has been publicly disclosed. The vendor was contacted but did not respond.
AI Severity Medium
Vendor FLIR
Product AX8
Affected Version 1.46.0, 1.46.1, 1.46.2, 1.46.3, 1.46.4, 1.46.5, 1.46.6, 1.46.7, 1.46.8, 1.46.9, 1.46.10, 1.46.11, 1.46.12, 1.46.13, 1.46.14, 1.46.15, 1.46.16

Additional Information

CVE List
CWE List CWE-79, CWE-94
Bulletin Family

Description

A vulnerability, which was classified as problematic, has been found in FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. The manipulation of the argument cmd leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Score Summary

Base Score: %!f(string=#) ()

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.