Stored XSS Vulnerability in TP-Link EAP and Omada Controllers
CVE-2018-10164
5.4MEDIUM
What is CVE-2018-10164?
The stored Cross-Site Scripting vulnerability in TP-Link's EAP Controller and Omada Controller affects specific Windows versions. Authenticated attackers can exploit this issue by injecting arbitrary web scripts or HTML through the portalPictureUpload feature, leading to potential unauthorized actions on behalf of users. It is crucial for users of the affected products to upgrade to version 2.6.1_Windows to mitigate this risk.