cross-site scripting nella endpoint / DroboAccess / DELETE_USER in Drobo 5N2 NAS versione 4.0.5-13.28.96115 consente agli aggressori di eseguire JavaScript tramite il parametro URL ""nomeutente"". |
https://blog.securityevaluators.com/call-me-a-doctor-new-vulnerabilities-in-drobo5n2-4f1d885df7fc https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14698 |
Vulnerabilità: CVE-2018-14698
