← Back

CVE-2019-3414

nvd nist
Published: Jul 22, 2019Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.0/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front end does not process the returned result from the interface properly, the malicious script may be executed and the user cookie or other important information may be stolen.

Affected (1)

Products: Zte: Otcp Firmware
1 product
Otcp Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.19.20.02
Running on/withPlatform Versions
Zte
Otcp
All versions

References (2)

Timeline

No history available yet.