Reflective XSS Vulnerability in ZTE's ZXCDN Product
CVE-2022-23137

6.1MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
11 May 2022

What is CVE-2022-23137?

A reflective cross-site scripting vulnerability has been identified in ZTE's ZXCDN product. This issue allows an attacker to craft a malicious URL that, when clicked by a user, triggers an XSS attack. By manipulating parameters in the content clearing request URL, an attacker can execute arbitrary scripts in the context of the user's browser, potentially leading to unauthorized access to sensitive information and session hijacking. This exploitation emphasizes the necessity for robust input validation and sanitization mechanisms to protect against such vulnerabilities.

Affected Version(s)

ZXCDN All versions up to ZXCDN-IAMV8.01.01.02

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-23137 : Reflective XSS Vulnerability in ZTE's ZXCDN Product