Cross-Site Scripting Vulnerability in Moxa AWK-3121 Devices
CVE-2018-10692
6.1MEDIUM
Summary
A security flaw has been identified in Moxa AWK-3121 1.14 devices where the session cookie named 'Password508' is missing the HttpOnly flag. This absence allows an attacker, capable of executing a cross-site scripting (XSS) attack, to easily access and steal the session cookie, potentially compromising user sessions and sensitive data.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved