vendor:
Routers2
by:
Lorenzo Di Fuccia
4.7
CVSS
MEDIUM
Reflected Cross-Site Scripting
79
CWE
Product Name: Routers2
Affected Version From: 2.24
Affected Version To: 2.24
Patch Exists: YES
Related CWE: CVE-2018-6193
CPE: 2.3:a:sshipway:routers2:2.24
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Perl
2018
Routers2 2.24 – Reflected Cross-Site Scripting
Routers2 is vulnerable to Reflected Cross-Site Scripting, affecting the 'rtr' GET parameter in a page=graph action to `cgi-bin/routers2.pl`.
Mitigation:
Update the program cloning the repo from GitHub or disable the 'paranoia' setting in the web section of the `routers2.conf`.