Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-23137: Security Bulletin Details

ZTE’s ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

CVE
#xss#vulnerability#web

Original release dat****e: May 10, 2022

CVE ID

CVE-2022-23137

CVSS 3.****1 Base Score

5.7 Medium (AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N)

Description

ZTE’s ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

Affected Products and Fixes

Product Name

Affected Version

Resolved Version

ZXCDN

All versions up to

ZXCDN-IAMV8.01.01.02

ZXCDN-IAMV8.01.01.02 SP1

Source

The vulnerability was found by ZTE’s internal test.

Update Records

May 10, 2022, initial.

Version Update Method

Please contact ZTE Global Customer Support Center to obtain the upgraded version.

Global Customer Support Center

http://support.zte.com.cn/support/web/Contact.aspx?_langType=en

ZTE PSIRT

https://www.zte.com.cn/global/cybersecurity/ztepsirt.html

Related news

CVE-2022-23137: Security Bulletin Details

ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907