CVE-2018-19927: XSS
Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the goform/zFormsavechanges sipnick parameter. The password of alphaadmin for the admin account may be used for authentication in some cases.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19927?
CVE-2018-19927 has a medium severity due to its capability for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2018-19927?
To fix CVE-2018-19927, update to Zenitel Norway IP-StationWeb firmware version 4.2.3.9 or later.
What types of attacks can CVE-2018-19927 be used for?
CVE-2018-19927 can be exploited for stored XSS attacks which can compromise the integrity of user sessions.
Which versions of Zenitel IP-StationWeb are affected by CVE-2018-19927?
Versions of Zenitel IP-StationWeb prior to 4.2.3.9 are affected by CVE-2018-19927.
Is authentication required to exploit CVE-2018-19927?
In some cases, exploiting CVE-2018-19927 may require authentication using the alphaadmin password.