CVE-2018-10108: XSS
D-Link DIR-815 REV. B (with firmware through DIR-815REVBFIRMWAREPATCH2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bscsmsinbox.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10108?
CVE-2018-10108 is a vulnerability found in D-Link DIR-815 REV. B devices with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01 that allows for XSS attacks.
How severe is CVE-2018-10108?
CVE-2018-10108 has a severity rating of 6.1 (medium).
How does CVE-2018-10108 affect D-Link DIR-815 REV. B devices?
CVE-2018-10108 affects D-Link DIR-815 REV. B devices with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01 by allowing XSS attacks in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
How can I fix CVE-2018-10108?
To fix CVE-2018-10108, users should upgrade the firmware on their D-Link DIR-815 REV. B devices to a version later than DIR-815_REVB_FIRMWARE_PATCH_2.07.B01.
What is the CWE ID associated with CVE-2018-10108?
CVE-2018-10108 is associated with CWE ID 79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').