vendor:
Aficio SP 5210SF Printer
by:
Olga Villagran
8.8
CVSS
HIGH
Code Injection - HTML Injection
94
CWE
Product Name: Aficio SP 5210SF Printer
Affected Version From: RICOH Aficio SP 5210SF Printer
Affected Version To: RICOH Aficio SP 5210SF Printer
Patch Exists: YES
Related CWE: N/A
CPE: h:ricoh:aficio_sp_5210sf_printer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
RICOH Aficio SP 5210SF Printer – ‘entryNameIn’ HTML Injection
A vulnerability in the RICOH Aficio SP 5210SF Printer allows an attacker to inject malicious HTML code via the 'entryNameIn' parameter in the 'adrsSetUser.cgi' script. An attacker can send a specially crafted HTTP POST request to the vulnerable script, which will execute the injected HTML code.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their systems to the latest version.