Reflected Cross-Site Scripting Vulnerability in Oracle WebCenter Interaction Portal
CVE-2018-16953
What is CVE-2018-16953?
The AjaxView::DisplayResponse() function in the portalpages.dll assembly of Oracle WebCenter Interaction Portal 10.3.3 is susceptible to reflected cross-site scripting (XSS). This vulnerability arises because user input from the 'name' parameter is reflected back in the server's response without proper encoding or sanitization. As a result, an attacker could exploit this vulnerability to execute arbitrary scripts in the context of an authenticated user, potentially leading to unauthorized actions and data leakage. It’s important to note that this version is out of support, which may complicate remediation efforts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved