Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References
Link | Resource |
---|---|
http://jvn.jp/en/jp/JVN63895206/index.html | Third Party Advisory |
https://www.necplatforms.co.jp/product/enkaku/info180702.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
No history.
Information
Published : 2018-07-26 17:29
Updated : 2018-10-02 18:02
NVD link : CVE-2018-0614
Mitre link : CVE-2018-0614
CVE.ORG link : CVE-2018-0614
JSON object : View
Products Affected
necplatforms
- calsos_csdj-h_firmware
- calsos_csdj-b
- calsos_csdx
- calsos_csdj-d_firmware
- calsos_csdx\(d\)_firmware
- calsos_csdx\(p\)_firmware
- calsos_csdj-a
- calsos_csdx\(s\)
- calsos_csdj-d
- calsos_csdx\(s\)_firmware
- calsos_csdx\(d\)
- calsos_csdx_firmware
- calsos_csdx\(p\)
- calsos_csdj-a_firmware
- calsos_csdj-h
- calsos_csdj-b_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')