CVE | CVE-2023-23313 |
CVE Title | |
Published Date | 2023-03-03T22:15Z |
Modified Date | 2023-03-10T14:52Z |
CWE Type | CWE-79 |
CVSS 3.x | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Description | Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-(cve-2023-23313)/ |
Reference Description | MISC https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-(cve-2023-23313)/ |
Reference URL | https://www.horizonsecurity.it/lang_EN/advisories/?a=22&title=Multiple+XSS+Stored+in+DrayTek+routers+web+interface++CVE202323313 |
Reference Description | MISC https://www.horizonsecurity.it/lang_EN/advisories/?a=22&title=Multiple+XSS+Stored+in+DrayTek+routers+web+interface++CVE202323313 |
Tags | Vendor Advisory |
Sources | NIST MITRE |