Cross-site scripting in RAID Web Console 3 - CVE-2018-3699

 

Cross-site scripting in RAID Web Console 3 - CVE-2018-3699

Published: November 13, 2018 / Updated: November 26, 2018


Vulnerability identifier: #VU16058
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2018-3699
CWE-ID: CWE-79
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows an adjacent attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. An adjacent attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability results in privilege escalation.


Affected software

RAID Web Console 3

How to mitigate CVE-2018-3699

Update to version 4.186.

RAID Web Console 3 - update to 4.186

External References

Related Security Bulletins