vendor:
TL-PS110U & TL-PS110P
by:
GotGeek Labs
8.8
CVSS
HIGH
Stored Cross-site Scripting
79
CWE
Product Name: TL-PS110U & TL-PS110P
Affected Version From: 9.08.47T 0016 (ZOT-PS-47/9.8.0016)
Affected Version To: 8.03.30T 0013 (ZOT-PS-30/8.3.0013)
Patch Exists: YES
Related CWE: N/A
CPE: h:tp-link:tl-ps110u
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2011
TP-Link TL-PS110U & TL-PS110P Cross-site Scripting Vulnerability
Web interface from TL-PS110U and TL-PS110P Print Servers are affected by stored cross-site scripting vulnerability because it fails to properly sanitize user-supplied input at 'NDSContext' field in 'NetWare NDS Settings' area. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Mitigation:
Ensure that user-supplied input is properly sanitized before being used in the application.