Логотип exploitDog
bind:CVE-2023-27990
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27990

Количество 3

Количество 3

nvd логотип

CVE-2023-27990

почти 3 года назад

The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-6qw9-cqm2-283v

почти 3 года назад

The XSS vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.

CVSS3: 3.5
EPSS: Низкий
fstec логотип

BDU:2023-08857

почти 3 года назад

Уязвимость микропрограммного обеспечения сетевых устройств ZyXEL USG, USG FLEX, USG20(W)-VPN и VPN, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольные сценарии на уязвимом устройстве

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-27990

The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-6qw9-cqm2-283v

The XSS vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.

CVSS3: 3.5
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-08857

Уязвимость микропрограммного обеспечения сетевых устройств ZyXEL USG, USG FLEX, USG20(W)-VPN и VPN, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольные сценарии на уязвимом устройстве

CVSS3: 8.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу