Unrated severityNVD Advisory· Published Mar 19, 2026· Updated Mar 23, 2026
Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php
CVE-2026-32843
Description
Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
Affected products
2<= commit f06bd20 (2023-04-26)+ 1 more
- (no CPE)range: <= commit f06bd20 (2023-04-26)
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.