First published: Mon Apr 01 2019(Updated: )
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsl-3782 Firmware | =1.01 | |
Dlink Dsl-3782 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17989 is a stored XSS vulnerability in the web interface on D-Link DSL-3782 devices with firmware 1.01.
An authenticated attacker can inject a JavaScript or HTML payload inside the ACL page and execute it in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
The severity of CVE-2018-17989 is medium (5.4).
D-Link DSL-3782 devices with firmware 1.01 are affected by CVE-2018-17989.
Yes, D-Link DSL-3782 devices with firmware 1.01 are vulnerable to CVE-2018-17989.