First published: Wed Oct 13 2021(Updated: )
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek VigorConnect | =1.6.0-beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-20128.
The affected software for this vulnerability is Draytek VigorConnect 1.6.0-B3.
The severity level of this vulnerability is medium.
The CWE ID associated with this vulnerability is CWE-79.
Yes, it is recommended to update to a version that has fixed this vulnerability.