First published: Thu Mar 19 2020(Updated: )
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canon Oce Colorwave 500 Firmware | <=4.0.0.0 | |
Canon Oce Colorwave 500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-10667 is medium.
Canon Oce Colorwave 500 Firmware version up to and including 4.0.0.0 is affected by CVE-2020-10667.
The vulnerability in the Canon Oce Colorwave 500 printer is a Stored XSS vulnerability in /TemplateManager/indexExternalLocation.jsp, with the vulnerable parameter being map(template_name).
Yes, the vulnerability CVE-2020-10667 is fixed in the latest version of Canon Oce Colorwave 500 firmware.
The Common Weakness Enumeration (CWE) associated with CVE-2020-10667 is CWE-79.