First published: Wed Sep 26 2018(Updated: )
On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ricoh MP 305+ Firmware | ||
Ricoh MP 305+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-17314.
The severity of CVE-2018-17314 is medium with a score of 6.1.
The affected software of CVE-2018-17314 is Ricoh Mp 305+ Firmware.
The HTML Injection vulnerability in CVE-2018-17314 can be exploited by injecting malicious HTML code into the entryNameIn parameter of the /web/entry/en/address/adrsSetUserWizard.cgi.
No, Ricoh Mp 305+ is not vulnerable to the Stored XSS vulnerability in CVE-2018-17314.