CVE-2016-0866

Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
Severity
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Atk. Vector
NETWORK
Atk. Complexity
LOW
Priv. Required
NONE
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
tollgradesmartgrid_lighthouse_sensor_management_system
𝑥
≤ 5.0
tollgradesmartgrid_lighthouse_sensor_management_system
4.1.0
𝑥
= Vulnerable software versions