There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
References
Link | Resource |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1028624 | Vendor Advisory |
Information
Published : 2023-01-06 11:15
Updated : 2023-01-12 06:35
NVD link : CVE-2022-39072
Mitre link : CVE-2022-39072
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
zte
- mf286r
- mf289d_firmware
- mf289d
- mf286r_firmware