vendor:
VDV-23: 115
by:
Nu11By73
5,4
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: VDV-23: 115
Affected Version From: 3.2.11-0.9.40
Affected Version To: 3.2.11-0.9.40
Patch Exists: Yes
Related CWE: CVE-2017-16843
CPE: h:vonage:vdv-23:115
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Vonage Home Router – Stored Xss
A stored XSS vulnerability exists in Vonage Home Router, which allows an authenticated attacker to inject malicious JavaScript code into the router's web interface. This can be exploited by sending a specially crafted HTTP POST request to the router's web interface. The malicious code is then stored in the router's web interface and is executed when a user visits the affected page.
Mitigation:
The vendor has released a patch to address this vulnerability.