There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
References
Link | Resource |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1028624 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: zte
Published: 2023-01-06T00:00:00
Updated: 2023-01-06T00:00:00
Reserved: 2022-08-31T00:00:00
Link: CVE-2022-39072
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-06T19:15:09.170
Modified: 2023-08-08T14:21:49.707
Link: CVE-2022-39072
JSON object: View
Redhat Information
No data.
CWE