CVE-2024-41583

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.
Configurations

No configuration.

History

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Los dispositivos DrayTek Vigor3910 hasta 4.3.2.6 son vulnerables a Cross Site Scripting (XSS) Almacenado por usuarios autenticados debido a una mala desinfección del nombre del enrutador.

03 Oct 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7
CWE CWE-79

03 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-03 19:15

Updated : 2024-10-04 13:50


NVD link : CVE-2024-41583

Mitre link : CVE-2024-41583

CVE.ORG link : CVE-2024-41583


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')