CVE-2019-3413

All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:netnumen_dap_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:netnumen_dap:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010797 - Vendor Advisory () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010797 - Vendor Advisory

Information

Published : 2019-06-11 20:29

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3413

Mitre link : CVE-2019-3413

CVE.ORG link : CVE-2019-3413


JSON object : View

Products Affected

zte

  • netnumen_dap_firmware
  • netnumen_dap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')