Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34360


A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.


Published

2023-07-31T06:15:09.873

Last Modified

2024-11-21T08:07:05.733

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System asus rt-ax88u_firmware ≤ 3.0.0.4.388.23110 Yes
Hardware asus rt-ax88u - No

References