Storage XSS Flaw in ZTE Server Management Software
CVE-2020-6872
What is CVE-2020-6872?
The ZTE server management software is susceptible to a storage-based cross-site scripting (XSS) vulnerability. An attacker can exploit this flaw by injecting malicious scripts through the login page, leading users to unwittingly execute the code in their browsers. This vulnerability can impact various versions across different models, potentially compromising user data and allowing unauthorized actions.
Affected Version(s)
<R5300G4?R8500G4?R5500G4> <R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020 < R5300G4V03.08.0100/V03.07.0300/V03.07.0200/V03.07.0108/V03.07.0100/V03.05.0047/V03.05.0046/V03.05.0045/V03.05.0044/V03.05.0043/V03.05.0040/V03.04.0020
<R5300G4?R8500G4?R5500G4> R8500G4V03.07.0103/V03.07.0101/V03.06.0100/V03.05.0400/V03.05.0020
<R5300G4?R8500G4?R5500G4> R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100> > R5500G4V03.08.0100/V03.07.0200/V03.07.0100/V03.06.0100