5.4
CVSSv3

CVE-2018-10314

Published: 10/05/2018 Updated: 13/06/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote malicious users to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.

Vulnerable Product Search on Vulmon Subscribe to Product

opmantek open-audit 2.2.0

Exploits

# Exploit Title: Open-AudIT Community - 220 – Cross-Site Scripting # Exploit Author: Tejesh Kolisetty # # Vendor Homepage: opmantekcom/ # Software Link: opmantekcom/network-tools-download/ # Affected Version: 220 # Category: WebApps # Tested on: Win7 Professional # CVE : CVE-2018-10314 # 1 Vendor Description: # Network ...
Open-AudIT Community version 220 suffers from multiple cross site scripting vulnerabilities ...