Cross-Site Scripting Vulnerability in Flexense SyncBreeze Affects Multiple Versions
CVE-2018-10563

6.1MEDIUM

Key Information:

Vendor

Flexense

Vendor
CVE Published:
2 May 2018

What is CVE-2018-10563?

A Cross-Site Scripting vulnerability exists in Flexense SyncBreeze, which allows attackers to inject arbitrary scripts through user input, affecting all tested versions from v10.1 to v10.7. This flaw can lead to session hijacking, data leakage, and other malicious activities, compromising the security of users interacting with the application.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.