Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.

Project Subscriptions

Vendors Products
Linkitonedevgroup Subscribe
Location Aware Sensor System (lass) Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Linkitonedevgroup
Linkitonedevgroup location Aware Sensor System (lass)
Vendors & Products Linkitonedevgroup
Linkitonedevgroup location Aware Sensor System (lass)

Thu, 19 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
Description Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing unencoded payloads in the site, city, district, channel, or apikey parameters to execute scripts in victims' browsers when they visit the page.
Title Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-20T18:11:16.895Z

Reserved: 2026-03-16T18:11:41.758Z

Link: CVE-2026-32843

cve-icon Vulnrichment

Updated: 2026-03-20T18:02:20.772Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-19T15:16:27.570

Modified: 2026-03-20T13:39:46.493

Link: CVE-2026-32843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:14:50Z

Weaknesses