4.3
CVSSv2

CVE-2018-1000611

Published: 09/07/2018 Updated: 06/09/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can result in Allows an malicious user to inject arbitrary web scripts or HTML into help and login pages. This attack appear to be exploitable via the victim opening a specially crafted URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openconext openconext engineblock

Exploits

OpenConext-EngineBlock versions 570 through 573suffers from a cross site scripting vulnerability ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 XSS vulnerabilities were found in multiple pages that allows an attacker to inject arbitrary web scripts The Twig PHP extension configuration was not sanitizing user input before display it to the user Issues fixed in version 574 and 580 Git commit here: githubcom/OpenConext/OpenCon ...