The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published: 2023-04-24T00:00:00

Updated: 2024-08-02T12:23:30.803Z

Reserved: 2023-03-09T00:00:00

Link: CVE-2023-27990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-24T18:15:09.440

Modified: 2024-02-02T17:08:15.513

Link: CVE-2023-27990

cve-icon Redhat

No data.