CVE-2019-25324: RICOH Web Image Monitor 1.09 - HTML Injection
RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-site scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25324?
CVE-2019-25324 is rated as a moderate severity vulnerability due to its potential to allow HTML injection via the Ricoh Web Image Monitor.
How can I fix CVE-2019-25324?
To fix CVE-2019-25324, update your Ricoh Web Image Monitor software to the latest version that addresses the HTML injection vulnerability.
What systems are affected by CVE-2019-25324?
CVE-2019-25324 affects Ricoh Web Image Monitor version 1.09, allowing exploitation of its HTML configuration features.
What type of attack does CVE-2019-25324 enable?
CVE-2019-25324 enables attackers to inject malicious HTML code, which can lead to various attacks such as phishing or redirecting users.
What are entryNameIn and entryDisplayNameIn in the context of CVE-2019-25324?
In the context of CVE-2019-25324, entryNameIn and entryDisplayNameIn are parameters susceptible to exploitation for HTML injection.