Cross-Site Scripting Vulnerability in ZTE ZXHN F670 Product
CVE-2019-3418

5.7MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
15 August 2019

What is CVE-2019-3418?

The ZTE ZXHN F670 product is susceptible to a cross-site scripting (XSS) vulnerability due to inadequate input validation. An authenticated user can potentially exploit this flaw to inject and execute malicious scripts, compromising the security of the platform. It is essential for users of affected versions to apply security measures to mitigate this risk effectively.

Affected Version(s)

ZXHN F670 <= unspecified

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.