First published: Wed Nov 22 2017(Updated: )
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei UMA Firmware | =v200r001 | |
Huawei UMA Firmware | =v300r001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8125 is considered a high-severity vulnerability due to its potential impact on application security through cross-site scripting.
To mitigate CVE-2017-8125, ensure that input validation is properly implemented to sanitize and validate user inputs on affected Huawei UMA versions.
CVE-2017-8125 affects Huawei UMA software versions V200R001 and V300R001.
Yes, CVE-2017-8125 can be exploited remotely if an attacker sends users a malicious link that executes cross-site scripting.
The potential impacts of CVE-2017-8125 include unauthorized access to sensitive information and the ability to execute arbitrary scripts in users' browsers.