CVE Feed

    Dashboard / CVE / CVE-2019-3414

    CVE-2019-3414

    All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front end does not process the returned result from the interface properly, the malicious script may be executed and the user cookie or other important information may be stolen.

    Published:Jul 22, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 22, 2019
    EPSS Score:0.00148
    CVSS Score:4.8

    Affected Products

    Vendor
    Zte
    Product
    Otcp
    Vendor
    Zte
    Product
    Otcp Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High