Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4frh-rw8g-vq9h

Опубликовано: 11 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

EPSS

Процентиль: 14%
0.00046
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.2
nvd
около 4 лет назад

There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

EPSS

Процентиль: 14%
0.00046
Низкий

Дефекты

CWE-79