Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
CVSS
No CVSS.
References
Configurations
No configuration.
History
17 Jun 2026, 10:36
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
19 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-19 15:16
Updated : 2026-07-14 19:16
NVD link : CVE-2026-32843
Mitre link : CVE-2026-32843
CVE.ORG link : CVE-2026-32843
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
