PT-2023-13683 · Zte · Zte Mobile Internet

Published

2023-01-06

·

Updated

2025-04-10

·

CVE-2022-39072

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Some ZTE Mobile Internet products (affected versions not specified)
Description The issue is related to a SQL injection vulnerability due to insufficient validation of the input parameters of the SNTP interface. An authenticated attacker could exploit this to execute stored XSS attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-39072

Affected Products

Zte Mobile Internet