6.1
CVSSv3

CVE-2016-8581

Published: 28/10/2016 Updated: 03/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM prior to 5.3.2 that allows an malicious user to steal session IDs of logged in users when the current sessions are viewed by an administrator.

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault unified security management

alienvault open source security information and event management

Exploits

Details ======= Product: Alienvault OSSIM/USM Vulnerability: Stored XSS Author: Peter Lapp, lappsec () gmail com CVE: CVE-2016-8581 CVSS: 35 Vulnerable Versions: <=531 Fixed Version: 532 Vulnerability Details ===================== A stored XSS vulnerability exists in the User-Agent header of the login process It's possible to inject a ...
Alienvault OSSIM/USM versions 531 and below suffer from a stored cross site scripting vulnerability ...