vendor:
Yealink Easy VoIP Phone
by:
Narendra Shinde
5,8
CVSS
MEDIUM
Improper Neutralization of Input during Web Page Generation ('Cross-site Scripting')
79
CWE
Product Name: Yealink Easy VoIP Phone
Affected Version From: Yealink Easy VoIP Phone
Affected Version To: Yealink Easy VoIP Phone
Patch Exists: YES
Related CWE: CVE-2012-1417
CPE: h:yealink:easy_voip_phone
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Yealink VOIP Phone Persistent Cross Site Scripting Vulnerability
Yealink Easy Voip phone is prone to multiple cross-site scripting vulnerabilities as the user-supplied input received via certain parameters is not properly sanitized. This can be exploited by submitting specially crafted input to the affected software. Successful exploitation could allow the attacker to execute arbitrary script code within the user's browser session in the security context of the targeted site. The attacker could redirect user to malicious site, gain access to user's cookies (including authentication cookies), if any, and launch other attacks.
Mitigation:
The vendor has released a patch to address this issue.