CVE-2018-13308: XSS
Published Nov 26, 2018
·Updated
Cross-site scripting in noticegen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of the cross-site scripting vulnerability in TOTOLINK A3002RU version 1.0.8?
The vulnerability ID of the cross-site scripting in TOTOLINK A3002RU version 1.0.8 is CVE-2018-13308.
2
What is the severity rating of CVE-2018-13308?
The severity rating of CVE-2018-13308 is medium.
3
How can an attacker exploit the CVE-2018-13308 vulnerability?
An attacker can exploit the CVE-2018-13308 vulnerability by modifying the "User phrases button" field to execute arbitrary JavaScript.
4
Which software versions of TOTOLINK A3002RU are affected by CVE-2018-13308?
The vulnerability affects TOTOLINK A3002RU version 1.0.8.
5
Is TOTOLINK A3002RU version 1.0.8 the only vulnerable version?
Yes, TOTOLINK A3002RU version 1.0.8 is the only vulnerable version.