First published: Wed Dec 18 2019(Updated: )
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-615 | =20.07 | |
D-Link DIR-615 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-19742 is considered medium due to its potential for blind XSS exploitation.
CVE-2019-19742 affects the User Account Configuration page of D-Link DIR-615 devices, allowing for blind XSS via the name field.
To fix CVE-2019-19742, update to the latest firmware version provided by D-Link that addresses this vulnerability.
Exploiting CVE-2019-19742 could allow an attacker to execute arbitrary JavaScript in the context of the user's browser.
CVE-2019-19742 specifically affects D-Link DIR-615 firmware version 20.07.