Vulnerabilities > Brightsign > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-18 CVE-2017-17737 Cross-site Scripting vulnerability in Brightsign 4K242 Firmware 6.2.63
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.
network
low complexity
brightsign CWE-79
6.1