CVE-2022-23137: XSS
Published May 11, 2022
·Updated
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
Affected Software
2 affected components
ZTE Zxcdn Firmware<zxcdn-iamv8.01.01.02
ZTE ZXCDN
Event History
May 11, 2022
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-23137?
CVE-2022-23137 is a reflective XSS vulnerability in ZTE's ZXCDN product.
2
How does CVE-2022-23137 work?
The attacker is able to modify the parameters in the content clearing request URL, and when a user clicks the URL, an XSS attack will be triggered.
3
What software is affected by CVE-2022-23137?
ZTE's ZXCDN product with firmware version zxcdn-iamv8.01.01.02 is affected.
4
What is the severity of CVE-2022-23137?
CVE-2022-23137 has a severity rating of 6.1 (medium).
5
How can I fix CVE-2022-23137?
To fix CVE-2022-23137, it is recommended to apply the latest firmware update provided by ZTE.