CVE-2018-1000528
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to have been fixed in after commit 56070d6289d47ba3f5918885954dcceb75606001.
GONICUS GOsa en versiones anteriores al commit con ID 56070d6289d47ba3f5918885954dcceb75606001 contiene una vulnerabilidad de Cross-Site Scripting (XSS) en el formulario de cambio de contraseña (html/password.php, #308) que puede resultar en la inyección de scripts web o HTML arbitrarios. El ataque parece ser explotable si una víctima abre una página web especialmente manipulada. La vulnerabilidad parece haber sido solucionada tras el commit con ID 56070d6289d47ba3f5918885954dcceb75606001.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-06-05 CVE Reserved
- 2018-06-26 CVE Published
- 2024-08-05 CVE Updated
- 2024-09-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/gosa-project/gosa-core/issues/14 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2018/07/msg00028.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/gosa-project/gosa-core/commit/56070d6289d47ba3f5918885954dcceb75606001 | 2018-08-30 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2018/dsa-4239 | 2018-08-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Gonicus Search vendor "Gonicus" | Gosa Search vendor "Gonicus" for product "Gosa" | - | - |
Affected
|