First published: Mon Apr 16 2018(Updated: )
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-815 Firmware | <=2.07.b01 | |
Dlink Dir-815 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10107 is a vulnerability found in D-Link DIR-815 REV. B devices with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01 that allows for cross-site scripting (XSS) attacks.
CVE-2018-10107 has a severity rating of 6.1, which is considered medium.
CVE-2018-10107 affects D-Link DIR-815 REV. B devices with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01 by allowing malicious actors to perform cross-site scripting attacks through the RESULT parameter in /htdocs/webinc/js/info.php.
To fix CVE-2018-10107, it is recommended to update the firmware of the D-Link DIR-815 REV. B device to a version that is not vulnerable.
More information about CVE-2018-10107 can be found at the following link: [Link](https://github.com/iceMatcha/Some-Vulnerabilities-of-D-link-Dir815/blob/master/Vulnerabilities_Summary.md)