First published: Tue Mar 31 2020(Updated: )
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Xgs2210-52hp Firmware | =4.50 | |
Zyxel XGS2210-52HP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-13495.
The severity of CVE-2019-13495 is medium (5.4).
The affected software version is Zyxel Xgs2210-52hp Firmware 4.50.
Remote authenticated users can inject arbitrary web script through the Name or Location field in the rpSys.html page.
No, Zyxel XGS2210-52HP is not vulnerable to this issue.