CVE-2019-18914

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/11/2021
Last modified:
15/11/2021

Description

A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* 2309025_582081 (excluding)
cpe:2.3:h:hp:laserjet_cm4540_mfp_cc419a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_cm4540_mfp_cc420a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_cm4540_mfp_cc421a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* 2309025_582098 (excluding)
cpe:2.3:o:hp:futuresmart_4:*:*:*:*:*:*:*:* 2410028_055010 (excluding)
cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_a2w75a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_a2w76a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_d7p70a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_d7p71a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_l3u51a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_l3u52a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_managed_flow_mfp_m880zm_a2w75a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_managed_flow_mfp_m880zm_a2w76a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:laserjet_managed_flow_mfp_m880zm_d7p70a:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools