vendor:
RICOH Printer
by:
Ismail Tasdelen
N/A
CVSS
N/A
Code Injection
Unknown
CWE
Product Name: RICOH Printer
Affected Version From: Aficio MP 301
Affected Version To: Aficio MP 301
Patch Exists: NO
Related CWE:
CPE: ricoh:aficio_mp_301_printer
Platforms Tested:
2018
RICOH Aficio MP 301 Printer – Cross-Site Scripting
On the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
Mitigation:
No specific mitigation mentioned.