CVE-2018-17313 | Ricoh MP C307 Wizard adrsSetUserWizard.cgi entryNameIn Stored cross site scripting (ID 149497 / EDB-45526)
A vulnerability has been found in Ricoh MP C307 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /web/entry/en/address/adrsSetUserWizard.cgi of the component Wizard. The manipulation of the argument entryNameIn as part of Parameter leads to cross site scripting (Stored).
This vulnerability is known as CVE-2018-17313. The attack can be launched remotely. Furthermore, there is an exploit available.