CVE-2023-28648: Propumpservice Osprey Pump Controller Firmware
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.
Affected products
- Propumpservice Osprey Pump Controller Firmware: version 1.01 only
Published 2023-03-28. Last modified 2026-06-17.