CVE-2017-2148
Description
Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
References
Vendor Advisory
Third Party AdvisoryVDB Entry
Third Party AdvisoryVDB Entry
CvssV3 impact
BaseSeverity | MEDIUM |
ConfidentialityImpact | LOW |
AttackComplexity | LOW |
Scope | CHANGED |
AttackVector | NETWORK |
AvailabilityImpact | NONE |
IntegrityImpact | LOW |
PrivilegesRequired | LOW |
BaseScore | 5.4 |
VectorString | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Version | 3.0 |
UserInteraction | REQUIRED |
CvssV2 impact
Version | 2.0 |
VectorString | AV:N/AC:M/Au:S/C:N/I:P/A:N |
AccessVector | NETWORK |
AccessComplexity | MEDIUM |
Authentication | SINGLE |
ConfidentialityImpact | NONE |
IntegrityImpact | PARTIAL |
AvailabilityImpact | NONE |
BaseScore | 3.5 |