CyberRota Analysis
AI-GeneratedA stored cross-site scripting (XSS) vulnerability exists in the web management interface of several Digi products, allowing a remote, authenticated administrator to inject malicious scripts into system configuration fields. This could lead to the execution of the injected script in the browsers of users accessing the affected pages, potentially compromising user data and session integrity. Organizations using these Digi devices, particularly those with remote administrative access, should prioritize addressing this vulnerability to mitigate risks associated with unauthorized script execution.
Original NVD Description
A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).