Reflected Cross-Site Scripting Vulnerability in Symantec Security Analytics
CVE-2018-12241

6.1MEDIUM

Key Information:

Vendor
Symantec Corporation
Status
Symantec Security Analytics (sa)
Vendor
CVE Published:
27 November 2018

Summary

The Symantec Security Analytics Web UI prior to version 7.3.4 has a vulnerability that allows remote attackers to exploit reflected cross-site scripting. By crafting a malicious URL that targets the Security Analytics interface, attackers can execute unsolicited malicious JavaScript within the user's browser session. This can lead to phishing attacks and unauthorized access, as users may be misled into executing harmful actions or revealing sensitive information, highlighting the need for immediate awareness and remediation.

Affected Version(s)

Symantec Security Analytics (SA) SA 7.x prior to 7.3.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.