There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190605-01-hedex-en | Vendor Advisory |
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190605-01-hedex-en | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190605-01-hedex-en - Vendor Advisory |
Information
Published : 2019-06-13 16:29
Updated : 2024-11-21 04:44
NVD link : CVE-2019-5286
Mitre link : CVE-2019-5286
CVE.ORG link : CVE-2019-5286
JSON object : View
Products Affected
huawei
- hedex_lite
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')