CVE-2018-17441

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dlink:central_wifimanager:*:*:*:*:*:*:*:*

History

26 Apr 2023, 19:36

Type Values Removed Values Added
CPE cpe:2.3:a:d-link:central_wifimanager:*:*:*:*:*:*:*:* cpe:2.3:a:dlink:central_wifimanager:*:*:*:*:*:*:*:*
First Time Dlink
Dlink central Wifimanager

Information

Published : 2018-10-08 16:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-17441

Mitre link : CVE-2018-17441

CVE.ORG link : CVE-2018-17441


JSON object : View

Products Affected

dlink

  • central_wifimanager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')