CVE-2018-15884: CSRF
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-15884.
What is the title of this vulnerability?
The title of this vulnerability is RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
How can this vulnerability be exploited?
This vulnerability can be exploited by performing HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
What is the severity of CVE-2018-15884?
The severity of CVE-2018-15884 is high with a CVSS score of 8.8.
Are there any known exploits for this vulnerability?
Yes, there are known exploits for this vulnerability. You can find them at the following references: http://packetstormsecurity.com/files/149082/RICOH-MP-C4504ex-Cross-Site-Request-Forgery.html and https://www.exploit-db.com/exploits/45264/