CVE-2018-17313 describes HTML Injection and Stored Cross-Site Scripting (XSS) vulnerabilities affecting RICOH MP C307 printers. These flaws allow attackers to inject malicious HTML or scripts into the device's address book via the entryNameIn parameter during address addition. With a CVSS score of 6.1 (Medium), the vulnerability requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), potentially leading to limited confidentiality and integrity impacts (C:L/I:L). While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists for a similar Ricoh printer model, and the CVE has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ricoh:mp_c307_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.