First published: Sun Dec 29 2019(Updated: )
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netis-systems Dl4343 Firmware | ||
Netis-systems Dl4343 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20073 is a vulnerability on Netis DL4323 devices that allows XSS attacks via the form2userconfig.cgi username parameter.
CVE-2019-20073 has a severity rating of 6.1 (medium).
The affected software is Netis-systems Dl4343 Firmware.
To fix CVE-2019-20073, it is recommended to update the Netis DL4323 device firmware to a patched version.
More information about CVE-2019-20073 can be found in the following references: 1. [Link 1] (https://drive.google.com/open?id=1CxLrSKAczEZpm_7FERIrCGGJAs2mp6Go) 2. [Link 2] (https://drive.google.com/open?id=1puObYuPWktesaVW1SO8uvSr1g4SnAtAw) 3. [Link 3] (https://fatihhcelik.blogspot.com/2019/12/stored-xss-on-username-input-netisdl4323.html)