First published: Sat Jul 06 2019(Updated: )
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Central Wifimanager | =1.03 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13374 is a cross-site scripting (XSS) vulnerability in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6.
CVE-2019-13374 allows remote attackers to inject arbitrary web script or HTML into the resource view in PayAction.class.php.
CVE-2019-13374 has a severity rating of 6.1, which is considered medium.
To fix CVE-2019-13374, update D-Link Central WiFi Manager to v1.03R0100_BETA6 or later.
CVE-2019-13374 is associated with CWE ID 79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').