CVE-2026-32843

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-03-19 15:16

Updated : 2026-07-14 19:16


NVD link : CVE-2026-32843

Mitre link : CVE-2026-32843

CVE.ORG link : CVE-2026-32843


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')