PT-2018-17254 · Netis · Netis Wf2419
Published
2018-01-25
·
Updated
2018-02-12
·
CVE-2018-5967
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Netis WF2419 version 2.2.36123
Description:
The issue allows for XSS via the
Description parameter on the "Bandwidth Control Rule Settings" page.Recommendations:
For Netis WF2419 version 2.2.36123, avoid using the
Description parameter in the Bandwidth Control Rule Settings page until the issue is resolved. As a temporary workaround, consider restricting access to the Bandwidth Control Rule Settings page to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netis Wf2419