First published: Tue Jan 07 2020(Updated: )
A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the victim's browser by tricking the victim into clicking on a crafted link. The payload was tested in Microsoft Internet Explorer 11.418.18362.0 and Microsoft Edge 44.18362.387.0 (Microsoft EdgeHTML 18.18362).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Watchguard Xmt515 Firmware | <=12.3 | |
WatchGuard XMT515 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18652 is a DOM based XSS vulnerability that affects the WatchGuard XMT515 firmware versions up to and including 12.3.
CVE-2019-18652 allows a remote attacker to execute JavaScript in the victim's browser by tricking them into clicking on a crafted link.
CVE-2019-18652 affects the WatchGuard XMT515 firmware versions up to and including 12.3.
CVE-2019-18652 has a severity level of 6.1, which is considered medium.
To mitigate CVE-2019-18652, it is recommended to update the WatchGuard XMT515 firmware to version 12.3 or higher.