PT-2018-9571 · Freshdns · Freshdns

Luelistao

·

Published

2018-12-20

·

Updated

2019-01-08

·

CVE-2018-1000847

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreshDNS versions 1.0.3 and prior
Description The issue allows for the execution of an attacker's JavaScript code in a victim's session due to a Cross Site Scripting (XSS) vulnerability in the Account data form and Zone editor. This can be exploited when an attacker stores a specially crafted string as their Full Name in their account details, and the victim, such as the administrator, opens the User List in the admin interface.
Recommendations For FreshDNS versions 1.0.3 and prior, update to version 1.0.5 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000847

Affected Products

Freshdns