PT-2018-9821 · Open Audit · Open-Audit Community

Tejesh Kolisetty

·

Publicado

2018-05-10

·

Atualizado

2018-06-13

·

CVE-2018-10314

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Open-AudIT Community version 2.2.0
Description: A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component. This is demonstrated by the action parameter in the "Discover -> Audit Scripts -> List Scripts -> Download" section.
Recommendations: For Open-AudIT Community version 2.2.0, consider restricting access to the Discover -> Audit Scripts -> List Scripts -> Download section until a patch is available. As a temporary workaround, avoid using crafted component names in this section to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10314

Produtos afetados

Open-Audit Community