First published: Mon Apr 16 2018(Updated: )
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-815 Firmware | <=2.07.b01 | |
Dlink Dir-815 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10108 is a vulnerability found in D-Link DIR-815 REV. B devices with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01 that allows for XSS attacks.
CVE-2018-10108 has a severity rating of 6.1 (medium).
CVE-2018-10108 affects D-Link DIR-815 REV. B devices with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01 by allowing XSS attacks in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
To fix CVE-2018-10108, users should upgrade the firmware on their D-Link DIR-815 REV. B devices to a version later than DIR-815_REVB_FIRMWARE_PATCH_2.07.B01.
CVE-2018-10108 is associated with CWE ID 79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').