CVE-2020-15895

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
22/07/2020
Last modified:
08/11/2023

Description

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-816l_firmware:2.06:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-816l_firmware:2.06.b09:beta:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-816l:b1:*:*:*:*:*:*:*