Cross-Site Scripting Vulnerability in Flexense DupScout Enterprise
CVE-2018-10566

6.1MEDIUM

Key Information:

Vendor

Flexense

Status
Vendor
CVE Published:
2 May 2018

What is CVE-2018-10566?

An XSS vulnerability exists in Flexense DupScout Enterprise versions 10.0.18 through 10.7, allowing attackers to inject malicious scripts via manipulated URLs or request parameters. This could result in unauthorized actions being executed in the context of a victim's session, potentially compromising sensitive user data and applications.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-10566 : Cross-Site Scripting Vulnerability in Flexense DupScout Enterprise