Reflective XSS Vulnerability in ZTE's ZXCDN Product
CVE-2022-23137
6.1MEDIUM
What is CVE-2022-23137?
A reflective cross-site scripting vulnerability has been identified in ZTE's ZXCDN product. This issue allows an attacker to craft a malicious URL that, when clicked by a user, triggers an XSS attack. By manipulating parameters in the content clearing request URL, an attacker can execute arbitrary scripts in the context of the user's browser, potentially leading to unauthorized access to sensitive information and session hijacking. This exploitation emphasizes the necessity for robust input validation and sanitization mechanisms to protect against such vulnerabilities.
Affected Version(s)
ZXCDN All versions up to ZXCDN-IAMV8.01.01.02
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
