First published: Wed Sep 26 2018(Updated: )
On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RICOH MP C6503 | ||
RICOH MP C6503 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-17311.
The Ricoh MP C6503 Firmware is affected by this vulnerability.
The severity of CVE-2018-17311 is medium with a severity value of 6.1.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-79.
To fix the HTML Injection and Stored XSS vulnerabilities, it is recommended to update the firmware of the RICOH MP C6503 Plus printer to the latest version provided by Ricoh.