Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-11073

Опубликовано: 28 сент. 2018
Источник: nvd
CVSS3: 6.5
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operations Console. A malicious Operations Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:emc:rsa_authentication_manager:8.3:p1:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.3:p2:*:*:*:*:*:*
cpe:2.3:a:rsa:authentication_manager:*:*:*:*:*:*:*:*
Версия до 8.3 (включая)

EPSS

Процентиль: 65%
0.00483
Низкий

6.5 Medium

CVSS3

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operations Console. A malicious Operations Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.

EPSS

Процентиль: 65%
0.00483
Низкий

6.5 Medium

CVSS3

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79