vendor:
N/A
by:
Yuval tisf Nativ
7,5
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
D-Link Persistent XSS
The page 'dhcpinfo.html' will list all machines connected to the network with hostname, IP, MAC and IP expiration. It is possible to store an XSS in this table by changing hostname.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.