CVE-2018-17313: XSS
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17313?
CVE-2018-17313 is a vulnerability that refers to HTML Injection and Stored XSS vulnerabilities in the RICOH MP C307 printer.
How does CVE-2018-17313 affect RICOH MP C307 printer?
CVE-2018-17313 allows attackers to inject malicious HTML code or execute malicious scripts on the RICOH MP C307 printer when adding addresses.
What is the severity of CVE-2018-17313?
CVE-2018-17313 has a severity value of 6.1 which is considered medium.
How can I fix CVE-2018-17313?
To fix CVE-2018-17313, it is recommended to apply the latest firmware updates for the RICOH MP C307 printer.
Where can I find more information about CVE-2018-17313?
You can find more information about CVE-2018-17313 on the following references: [Link 1](http://packetstormsecurity.com/files/149497/RICOH-MP-C307-Printer-Cross-Site-Scripting.html) and [Link 2](https://www.exploit-db.com/exploits/45526/).