PT-2020-9376 · Xerox · Phaser 3320+1

Published

2020-03-13

·

Updated

2020-03-18

·

CVE-2019-13167

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Xerox Web Application versions prior to the fixed version
Description: The issue concerns Stored XSS vulnerabilities found in the Xerox Web Application, which is used by certain printers, including the Phaser 3320. These vulnerabilities can be exploited to hijack the administrator's session in the web application or execute unwanted actions.
Recommendations: For versions prior to the fixed version, update to the latest version to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13167

Affected Products

Phaser 3320
Xerox Web Application