XSS Vulnerability on Technicolor TC7300 Devices
CVE-2019-17523
5.4MEDIUM
What is CVE-2019-17523?
An XSS vulnerability exists in Technicolor TC7300 STFA.51.20 devices, permitting remote attackers to inject malicious web scripts via the 'FileName' parameter on the /FTPDiag.asp page. This flaw can be exploited to execute unauthorized scripts in the context of user sessions, potentially leading to data theft or service disruption.