The server management software module of ZTE has a storage XSS vulnerability
Published Jul 20, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.74%
Description
The server management software module of ZTE has a storage XSS vulnerability. The attacker inserts some attack codes through the foreground login page, which will cause the user to execute the predefined malicious script in the browser. This affects <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020;R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020;R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100>.
Affected products
No data.
Configuration 1
- 03.05.0020
- 03.05.0400
- 03.06.0100
- 03.07.0101
- 03.07.0103
Configuration 2
- 03.06.0100
- 03.07.0100
- 03.07.0200
- 03.08.0100
Configuration 3
- 03.04.0020
- 03.05.0040
- 03.05.0043
- 03.05.0044
- 03.05.0045
- 03.05.0046
- 03.05.0047
- 03.07.0100
- 03.07.0108
- 03.07.0200
- 03.07.0300
- 03.08.0100
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013203 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1013203 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.