CVE-2019-20070: XSS
Published Dec 29, 2019
·Updated
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).
Affected Software
2 affected components
netis-systems Dl4343 Firmware
netis-systems Dl4343
Event History
Dec 29, 2019
CVE Published
via MITRE·11:30 PM
Data Sourced
via MITRE·11:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-20070.
2
What is the severity of CVE-2019-20070?
The severity of CVE-2019-20070 is medium with a CVSS score of 6.1.
3
How does the XSS vulnerability occur in Netis DL4323 devices?
The XSS vulnerability occurs via the urlFQDN parameter to form2url.cgi, specifically in the Keyword field of the URL Blocking Configuration.
4
Is Netis DL4343 affected by this vulnerability?
No, Netis DL4343 devices are not affected by CVE-2019-20070.
5
How can I fix the XSS vulnerability in Netis DL4323 devices?
To fix the XSS vulnerability, it is recommended to apply the latest firmware update provided by Netis Systems.