Stored XSS Vulnerability in D-Link DSL-2680 Web Administration Interface
CVE-2019-19222
5.4MEDIUM
Summary
The D-Link DSL-2680 web administration interface is susceptible to a Stored XSS vulnerability. Authenticated attackers can exploit this weakness by submitting a specially crafted POST request to the info.html page. This allows the injection of arbitrary JavaScript code, potentially enabling attackers to execute malicious scripts within the context of the user's session, leading to unauthorized actions and data exposure.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved