In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: rapid7

Published: 2017-12-20T22:00:00

Updated: 2017-12-20T21:57:01

Reserved: 2017-01-09T00:00:00


Link: CVE-2017-5256

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-12-20T22:29:00.400

Modified: 2019-10-09T23:28:16.120


Link: CVE-2017-5256

JSON object: View

cve-icon Redhat Information

No data.

CWE