cbcvebase.
CVE-2018-17441
published 2018-10-08

CVE-2018-17441: An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EXPLOIT
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkcentral_wifimanager1.00 – 1.03