Multiple cross-site scripting (XSS) vulnerabilities in Highwall Enterprise and Highwall Endpoint 4.0.2.11045 management interface allow remote attackers to inject arbitrary web script or HTML via (1) an Access Point with a crafted SSID, (2) the name of the sensor WIDS, (3) the name of the Highwall EndPoint workstation, or other unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Highwall_endpoint | Mobilesecure | 4.0.2.11045 (including) | 4.0.2.11045 (including) |
Highwall_enterprise | Mobilesecure | 4.0.2.11045 (including) | 4.0.2.11045 (including) |