Cross-Site Scripting Vulnerability in TP-Link Devices
CVE-2017-17745
5.4MEDIUM
What is CVE-2017-17745?
A cross-site scripting (XSS) vulnerability exists in the system_name_set.cgi file of TP-Link TL-SG108E 1.0.0. This flaw permits authenticated remote attackers to inject malicious JavaScript through the 'sysName' parameter. Exploiters can leverage this vulnerability to manipulate user sessions and perform unauthorized actions on behalf of legitimate users, posing a significant risk to the security and integrity of the affected systems.