CVE-2019-10634: XSS
Published Apr 9, 2019
·Updated
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
Affected Software
2 affected components
Zyxel NAS326<=5.21
Zyxel NAS326
Event History
Apr 9, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is CVE-2019-10634?
CVE-2019-10634 is an XSS vulnerability in the Zyxel NAS 326 version 5.21 and below.
2
How does CVE-2019-10634 work?
CVE-2019-10634 allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
3
What is the severity of CVE-2019-10634?
CVE-2019-10634 has a severity rating of 5.4 (Medium).
4
How can I fix CVE-2019-10634?
To fix CVE-2019-10634, you should update the Zyxel NAS 326 firmware to a version above 5.21.
5
Where can I find more information about CVE-2019-10634?
You can find more information about CVE-2019-10634 at http://maxwelldulin.com/BlogPost?post=3236967424.