CVE-2019-19742: XSS
Published Dec 18, 2019
·Updated
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
Affected Software
2 affected components
Dlink Dir-615 Firmware=20.07
Dlink Dir-615
Event History
Dec 18, 2019
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19742?
The severity of CVE-2019-19742 is considered medium due to its potential for blind XSS exploitation.
2
How does CVE-2019-19742 affect D-Link DIR-615 devices?
CVE-2019-19742 affects the User Account Configuration page of D-Link DIR-615 devices, allowing for blind XSS via the name field.
3
How do I fix CVE-2019-19742?
To fix CVE-2019-19742, update to the latest firmware version provided by D-Link that addresses this vulnerability.
4
What are the potential impacts of exploiting CVE-2019-19742?
Exploiting CVE-2019-19742 could allow an attacker to execute arbitrary JavaScript in the context of the user's browser.
5
Which firmware versions are affected by CVE-2019-19742?
CVE-2019-19742 specifically affects D-Link DIR-615 firmware version 20.07.