Skip to content

Latest commit

 

History

History
17 lines (11 loc) · 864 Bytes

CVE-2021-20137.md

File metadata and controls

17 lines (11 loc) · 864 Bytes

Description

A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.

POC

Reference

Github

No PoCs found on GitHub currently.