CVE-2018-8827
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
03/01/2019
Last modified:
15/01/2019
Description
The admin web interface on Technicolor MediaAccess TG789vac v2 HP devices with firmware v16.3.7190-2761005-20161004084353 displays unsanitised user input, which allows an unauthenticated malicious user to embed JavaScript into the Log viewer interface via a crafted HTTP Referer header, aka XSS.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:technicolor:tg789vac_firmware:16.3.7190-2761005-20161004084353:*:*:*:*:*:*:* | ||
| cpe:2.3:h:technicolor:tg789vac:2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



