Homeautomation Project

Homeautomation

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 27.04.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:58

HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to exe...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 27.04.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:58

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform...

Exploit
  • EPSS 2.38%
  • Veröffentlicht 27.04.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:59

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a special...

Exploit
  • EPSS 1.17%
  • Veröffentlicht 27.04.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:00

HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute arbitrary shell commands as the web user via the 'set_command_on' and '...

Exploit
  • EPSS 1.87%
  • Veröffentlicht 27.04.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:00

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.