vendor:
ZNID GPON 2426A EU
by:
Adam Ziaja
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: ZNID GPON 2426A EU
Affected Version From: S3.1.285
Affected Version To: S3.0.738
Patch Exists: YES
Related CWE: CVE-2019-10677
CPE: h:dasan_zhone:znid_gpon_2426a_eu
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Multiple Cross-Site Scripting (XSS) in DASAN Zhone ZNID GPON 2426A EU
Multiple Cross-Site Scripting (XSS) in the web interface of DASAN Zhone ZNID GPON 2426A EU version S3.1.285 application allows a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameters.
Mitigation:
Input validation, output encoding, and content security policy can be used to mitigate XSS attacks.