CVE-2013-2507: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware G (1.03) allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/logtonet.html or (2) kind parameter to fax/copysettings.html, a different vulnerability than CVE-2013-2670 and CVE-2013-2671.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2507?
CVE-2013-2507 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-2507?
To fix CVE-2013-2507, you should update the firmware of the Brother MFC-9970CDW printer to the latest version provided by Brother.
What are the exploit vectors for CVE-2013-2507?
CVE-2013-2507 can be exploited by injecting arbitrary web scripts through the id parameter in admin/log_to_net.html or the kind parameter in fax/copy_settings.html.
Who is affected by CVE-2013-2507?
The vulnerability affects users of the Brother MFC-9970CDW printer with firmware version g(1.03).
Is there a known workaround for CVE-2013-2507?
A known workaround for CVE-2013-2507 includes restricting access to the printer's web interface to trusted networks only.