Description
V-SOL GPON/EPON OLT Platform v2.03 contains multiple reflected cross-site scripting vulnerabilities due to improper input sanitization in various script parameters. Attackers can exploit these vulnerabilities by injecting malicious HTML and script code to execute arbitrary scripts in a victim's browser session.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
V2.03.54R
V2.03.52R
V2.03.49
V2.03.47
V2.03.40
V2.03.26
V2.03.24
V1.8.6
V1.4
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5537.php
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5537.php (Zero Science Lab Vulnerability Advisory)
packetstormsecurity.com/files/154631 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/167864 (IBM X-Force Vulnerability Exchange)
cxsecurity.com/issue/WLB-2019090194 (CXSecurity Vulnerability Database)
www.vsolcn.com/ (VSOL Vendor Homepage)