vendor:
RICOH Printer
by:
Ismail Tasdelen
6.1
CVSS
MEDIUM
Code Injection
79
CWE
Product Name: RICOH Printer
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE: CVE-2019-11844
CPE: h:ricoh:sp_4520dn
Platforms Tested:
2019
RICOH SP 4520DN Printer – HTML Injection
An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN printer via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn or entryDisplayNameIn parameter. An attacker can inject arbitrary HTML code into the affected parameter, potentially leading to code execution or information disclosure.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest firmware or software updates provided by the vendor.