Vulnerability Name: | CVE-2018-1000528 (CCN-145570) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2018-05-24 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2018-05-24 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-08-30 | ||||||||||||||||||||||||||||||||||||||||
Summary: | GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to have been fixed in after commit 56070d6289d47ba3f5918885954dcceb75606001. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-1000528 Source: XF Type: UNKNOWN gonicusgosa-cve20181000528-xss(145570) Source: MISC Type: Patch, Third Party Advisory https://github.com/gosa-project/gosa-core/commit/56070d6289d47ba3f5918885954dcceb75606001 Source: CCN Type: GOsa GIT Repository Server-Side Reflected XSS via POST to /gosa/password.php #14 Source: MISC Type: Third Party Advisory https://github.com/gosa-project/gosa-core/issues/14 Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20180720 [SECURITY] [DLA 1436-1] gosa security update Source: DEBIAN Type: Third Party Advisory DSA-4239 Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-1000528 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |