PT-2017-14983 · Tp Link · Tp-Link Tl-Sg108E
James Mclean
·
Published
2017-12-20
·
Updated
2018-01-05
·
CVE-2017-17745
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-SG108E version 1.0.0
Description
A cross-site scripting (XSS) issue exists, allowing authenticated remote attackers to submit arbitrary JavaScript via the
sysName parameter in the system name set.cgi file.Recommendations
For TP-Link TL-SG108E version 1.0.0, avoid using the
sysName parameter in the system name set.cgi file until a fix is available. As a temporary workaround, consider restricting access to the system name set.cgi file to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-Sg108E