PT-2018-11272 · Valeuraddons · Valeuraddons German Spelling Dictionary

Published

2018-08-13

·

Updated

2018-10-11

·

CVE-2018-12587

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions valeuraddons German Spelling Dictionary version 1.3
Description A cross-site scripting issue was discovered, allowing remote attackers to inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar, potentially leading to unauthorized actions.
Recommendations For valeuraddons German Spelling Dictionary version 1.3, as a temporary workaround, consider restricting access to the ajax query parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12587

Affected Products

Valeuraddons German Spelling Dictionary