#VU16058 Cross-site scripting in RAID Web Console 3 - CVE-2018-3699

 

#VU16058 Cross-site scripting in RAID Web Console 3 - CVE-2018-3699

Published: November 13, 2018 / Updated: November 26, 2018


Vulnerability identifier: #VU16058
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-3699
CWE-ID: CWE-79
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
RAID Web Console 3
Software vendor:
Intel

Description

The disclosed vulnerability allows an adjacent attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. An adjacent attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability results in privilege escalation.


Remediation

Update to version 4.186.

External links