Cross-Site Scripting Flaw in REDAXO Media Manager by REDAXO
CVE-2018-18199

6.1MEDIUM

Key Information:

Vendor

Redaxo

Status
Vendor
CVE Published:
9 October 2018

What is CVE-2018-18199?

A Cross-Site Scripting vulnerability exists in the Media Manager component of REDAXO versions prior to 5.6.4. This security issue allows an attacker to inject malicious scripts into web pages viewed by users, potentially leading to session hijacking or data theft. Users are encouraged to update to the latest version to mitigate this risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2018-18199 : Cross-Site Scripting Flaw in REDAXO Media Manager by REDAXO