5.4
CVSSv3

CVE-2018-15903

Published: 08/10/2018 Updated: 26/11/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Discuss v1.2.1 module in Claromentis 8.2.2 is vulnerable to stored Cross Site Scripting (XSS). An authenticated attacker will be able to place malicious JavaScript in the discussion forum, which is present in the login landing page. A low privilege user can use this to steal the session cookies from high privilege accounts and hijack these, enabling them to hijack the elevated session and perform actions in their security context.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

claromentis claromentis 8.2.2

Exploits

Claromentis Discuss module version 121 suffers from a stored cross site scripting vulnerability ...

Mailing Lists

Issue: Stored Cross site Scripting (XSS) on Discuss Module v121 in Claromentis intranet application Reserved CVE: CVE-2018-15903 # Vulnerability OverviewThe Discuss v121 module in Claromentis 822 is vulnerable to Stored Cross Site Scripting (XSS) An authenticated attacker is able to place malicious JavaScript in the discussion forum, which ...