XSS Vulnerability in ASUSTOR Data Master by ASUSTOR
CVE-2018-15699
6.1MEDIUM
What is CVE-2018-15699?
ASUSTOR Data Master versions up to 3.1.5 are susceptible to an XSS vulnerability due to improper handling of HTTP requests for configuration files. This flaw allows a man-in-the-middle attacker to inject malicious JavaScript into the configuration files, potentially leading to unauthorized actions and data exposure when users interact with the affected service.
Affected Version(s)
ASUSTOR Data Master 3.1.5 and below