PT-2018-11070 · Symantec · Symantec Security Analytics

Publicado

2018-11-27

·

Atualizado

2019-02-11

·

CVE-2018-12241

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Symantec Security Analytics (SA) versions prior to 7.3.4
Description The issue allows a remote attacker to craft a malicious URL for the SA web UI, targeting users with phishing attacks or social engineering techniques. A successful attack enables injecting malicious JavaScript code into the SA web UI client application.
Recommendations For Symantec Security Analytics (SA) versions prior to 7.3.4, update to version 7.3.4 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12241

Produtos afetados

Symantec Security Analytics