CVE-2018-13312: XSS
Published Nov 26, 2018
·Updated
Cross-site scripting in noticegen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
Affected Software
2 affected components
TOTOLINK A3002ru Firmware=1.0.8
TOTOLINK A3002RU
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13312?
CVE-2018-13312 is a cross-site scripting vulnerability in notice_gen.htm in TOTOLINK A3002RU version 1.0.8.
2
How does CVE-2018-13312 work?
CVE-2018-13312 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
3
How severe is CVE-2018-13312?
CVE-2018-13312 has a severity rating of 6.1, which is considered medium.
4
What software versions are affected by CVE-2018-13312?
TOTOLINK A3002RU version 1.0.8 is affected by CVE-2018-13312.
5
How can I fix CVE-2018-13312?
To fix CVE-2018-13312, update TOTOLINK A3002RU firmware to a version that is not vulnerable.