Vulnerability Description
On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ricoh | Mp 305\+ Firmware | - |
| Ricoh | Mp 305\+ | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/149501/RICOH-MP-305-Printer-Cross-Site-ScriExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/149501/RICOH-MP-305-Printer-Cross-Site-ScriExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-17314?
CVE-2018-17314 is a vulnerability with a CVSS score of 6.1 (MEDIUM). On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUs...
How severe is CVE-2018-17314?
CVE-2018-17314 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17314?
Check the references section above for vendor advisories and patch information. Affected products include: Ricoh Mp 305\+ Firmware, Ricoh Mp 305\+.