3.5
CVSSv2

CVE-2018-11581

Published: 01/06/2018 Updated: 16/11/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote malicious users to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

Vulnerable Product Search on Vulmon Subscribe to Product

brother hl-l2340d_firmware

brother hl-l2380dw_firmware

Exploits

# Exploit Title: [ XSS at Brother HL series printers] # Date: [30052018] # Exploit Author: [Huy Kha] # Vendor Homepage: [supportbrothercom] # Software Link: [ Website ] # Version: Brother HL series printers # Tested on: Mozilla FireFox # Reflected XSS Payload : "--!><Svg/OnLoad=(confirm)(1)>" # Description : Sta ...