Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
References
Link | Resource |
---|---|
https://github.com/reevesrs24/cve/blob/master/D-Link_DIR-615/xss_UPnP/dlink_dir615_xss_upnp.md | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-08-25 12:29
Updated : 2021-04-23 09:43
NVD link : CVE-2018-15875
Mitre link : CVE-2018-15875
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
dlink
- dir-615_firmware
- dir-615