Reflective XSS Vulnerability in ZTE's ZXCDN Product
CVE-2022-23137
6.1MEDIUM
What is CVE-2022-23137?
A reflective cross-site scripting vulnerability has been identified in ZTE's ZXCDN product. This issue allows an attacker to craft a malicious URL that, when clicked by a user, triggers an XSS attack. By manipulating parameters in the content clearing request URL, an attacker can execute arbitrary scripts in the context of the user's browser, potentially leading to unauthorized access to sensitive information and session hijacking. This exploitation emphasizes the necessity for robust input validation and sanitization mechanisms to protect against such vulnerabilities.
Affected Version(s)
ZXCDN All versions up to ZXCDN-IAMV8.01.01.02
