CVE-2018-17314: XSS
Published Sep 26, 2018
·Updated
On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
Affected Software
2 affected components
Ricoh Mp 305\+ Firmware
Ricoh Mp 305\+
Event History
Sep 26, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-17314.
2
What is the severity of CVE-2018-17314?
The severity of CVE-2018-17314 is medium with a score of 6.1.
3
What is the affected software of CVE-2018-17314?
The affected software of CVE-2018-17314 is Ricoh Mp 305+ Firmware.
4
How can the HTML Injection vulnerability be exploited in CVE-2018-17314?
The HTML Injection vulnerability in CVE-2018-17314 can be exploited by injecting malicious HTML code into the entryNameIn parameter of the /web/entry/en/address/adrsSetUserWizard.cgi.
5
Is Ricoh Mp 305+ vulnerable to the Stored XSS vulnerability in CVE-2018-17314?
No, Ricoh Mp 305+ is not vulnerable to the Stored XSS vulnerability in CVE-2018-17314.