A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
References
Link Resource
https://telegra.ph/XSS-in-BDCOM-OLT-P3310D-2AC-07-29 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-08-29T00:00:00

Updated: 2023-08-29T19:23:52.645000

Reserved: 2023-08-07T00:00:00


Link: CVE-2023-39678

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-29T20:15:10.133

Modified: 2023-09-01T14:56:42.557


Link: CVE-2023-39678

JSON object: View

cve-icon Redhat Information

No data.

CWE