Cross-site Scripting Vulnerability in Seagate NAS OS
CVE-2018-12299

5.4MEDIUM

Key Information:

Vendor

Seagate

Status
Vendor
CVE Published:
13 May 2019

What is CVE-2018-12299?

A cross-site scripting vulnerability exists in the filebrowser component of Seagate NAS OS version 4.3.15.1. This flaw enables attackers to upload file names containing malicious JavaScript, which can be executed when other users interact with the compromised files. Such vulnerabilities pose significant risks by enabling unauthorized actions on behalf of users, potentially leading to data breaches or further exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.