Storage XSS Flaw in ZTE Server Management Software
CVE-2020-6872

6.1MEDIUM

Key Information:

Vendor

Zte

Vendor
CVE Published:
20 July 2020

What is CVE-2020-6872?

The ZTE server management software is susceptible to a storage-based cross-site scripting (XSS) vulnerability. An attacker can exploit this flaw by injecting malicious scripts through the login page, leading users to unwittingly execute the code in their browsers. This vulnerability can impact various versions across different models, potentially compromising user data and allowing unauthorized actions.

Affected Version(s)

<R5300G4?R8500G4?R5500G4> <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020 < R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020

<R5300G4?R8500G4?R5500G4> R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020

<R5300G4?R8500G4?R5500G4> R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100> > R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.