CVE-2018-13323: XSS
Published Nov 26, 2018
·Updated
Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via the "username" cookie.
Affected Software
2 affected components
Buffalo Ts5600d1206 Firmware=3.61-0.10
Buffalo TS5600D1206
Event History
Nov 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting vulnerability?
The vulnerability ID for this cross-site scripting vulnerability is CVE-2018-13323.
2
What is the affected software?
The affected software is Buffalo TS5600D1206 version 3.61-0.10.
3
How does this vulnerability allow attackers to execute JavaScript?
This vulnerability allows attackers to execute JavaScript via the "username" cookie.
4
What is the severity of CVE-2018-13323?
The severity of CVE-2018-13323 is medium with a CVSS score of 6.1.
5
How can I fix this cross-site scripting vulnerability?
To fix this vulnerability, update Buffalo TS5600D1206 firmware to version 3.61-0.11 or later.