https://sku11army.blogspot.com/2020/01/lifesize-devices-allow-xss-via.html
### lifesize devices allow XSS via the interface/interface.php brand parameter - CVE-2018-17981
[![](https://images.seebug.org/1583459705947-w331s)](https://images.seebug.org/1583459705947-w331s)
lifesize is a device for video conferences. when entering the web application
a popup will be displayed to execute flash, taking that URL and injecting
javascript in the "brand" parameter we will see how that code is executed
evidencing a cross site scripting
Affected Versions:
**_lifesize express - ls ex2_4.7.10 2000 (14)_**
**_Lifesize Room220i - LS_RM2_4.11.8 (14)_**
[![](https://images.seebug.org/1583459709753-w331s)](https://images.seebug.org/1583459709753-w331s)
[![](https://images.seebug.org/1583459714636-w331s)](https://images.seebug.org/1583459714636-w331s)
By: @linuxmonr4
暂无评论