CVE-2018-17310 EXPLOIT
6.1
MEDIUM · CVSS 3.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
Scoring
| CVSS | 6.1 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 2.32% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-09-26 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| ricoh | mp c1803 jpn |
| ricoh | mp c1803 jpn firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RICOH MP C1803 JPN Printer - Cross-Site Scripting | 2018-10-03 |
References
→ the Explorer · watch your stack · NVD