Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.
2020-01-31T22:15:10.293
2024-11-21T02:08:53.623
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nokia | 1830_photonic_service_switch-4_firmware | ≤ 6.0 | Yes |
Hardware | nokia | 1830_photonic_service_switch-4 | - | No |
Operating System | nokia | 1830_photonic_service_switch-16_firmware | ≤ 6.0 | Yes |
Hardware | nokia | 1830_photonic_service_switch-16 | - | No |
Operating System | nokia | 1830_photonic_service_switch-32_firmware | ≤ 6.0 | Yes |
Hardware | nokia | 1830_photonic_service_switch-32 | - | No |