
Reflected XSS in Ruckus Unleashed 200.13.6.1.319 via the name parameter.
A reflected cross-site scripting (XSS) vulnerability exists in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
Ruckus Wireless
Controller-less Systems (RUCKUS Unleashed)
200.13.6.1.319
/selfguestpass/guestAccessSubmit.jsp
name
https://192.168.1.51/selfguestpass/guestAccessSubmit.jsp?cookie=null&tip=5&name=</p><form>

The application reflects unsanitized user-controlled input from the name parameter back into the page response, enabling arbitrary JavaScript execution.
An attacker can execute JavaScript in the victim’s browser, leading to session hijacking, credential theft, forced redirection, or UI manipulation.
Huthaifa Qashou