CVE-2020-10670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
19/03/2020
Last modified:
23/03/2020

Description

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canon:oce_colorwave_500_firmware:*:*:*:*:*:*:*:* 4.0.0.0 (including)
cpe:2.3:h:canon:oce_colorwave_500:-:*:*:*:*:*:*:*