First published: Wed May 11 2022(Updated: )
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Zxcdn Firmware | <zxcdn-iamv8.01.01.02 | |
Zte Zxcdn |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23137 is a reflective XSS vulnerability in ZTE's ZXCDN product.
The attacker is able to modify the parameters in the content clearing request URL, and when a user clicks the URL, an XSS attack will be triggered.
ZTE's ZXCDN product with firmware version zxcdn-iamv8.01.01.02 is affected.
CVE-2022-23137 has a severity rating of 6.1 (medium).
To fix CVE-2022-23137, it is recommended to apply the latest firmware update provided by ZTE.