On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
References
Link Resource
https://medium.com/zero2flag/cve-2019-18203-bfa65918e591 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-10-21T17:35:31

Updated: 2019-10-21T17:35:31

Reserved: 2019-10-19T00:00:00


Link: CVE-2019-18203

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-10-21T18:15:10.617

Modified: 2019-10-24T15:49:32.793


Link: CVE-2019-18203

JSON object: View

cve-icon Redhat Information

No data.

CWE