CVE-2018-13310: XSS
Published Nov 26, 2018
·Updated
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13310?
CVE-2018-13310 is a vulnerability in TOTOLINK A3002RU version 1.0.8 that allows attackers to execute arbitrary JavaScript via the user's username.
2
How severe is CVE-2018-13310?
CVE-2018-13310 has a severity rating of medium, with a score of 6.1.
3
Which software version is affected by CVE-2018-13310?
TOTOLINK A3002RU version 1.0.8 is affected by CVE-2018-13310.
4
How can an attacker exploit CVE-2018-13310?
An attacker can exploit CVE-2018-13310 by injecting arbitrary JavaScript through the user's username in the password.htm page of TOTOLINK A3002RU version 1.0.8.
5
Is TOTOLINK A3002RU version 1.0.8 the only affected software version?
Yes, TOTOLINK A3002RU version 1.0.8 is the only affected software version by CVE-2018-13310.