JavaScript Injection Vulnerability in Micro Focus Solutions Business Manager
CVE-2018-7681

4.8MEDIUM

Key Information:

Vendor
CVE Published:
21 June 2018

What is CVE-2018-7681?

Micro Focus Solutions Business Manager versions before 11.4 have a security flaw that allows the embedding of JavaScript in URLs within the 'Favorites' folder. Users with specific administrative privileges could exploit this vulnerability, potentially affecting other users within the system. This poses a significant risk as it could lead to unauthorized actions or data exposure on behalf of affected users.

Affected Version(s)

Solutions Business Manager 11.4 Solutions Business Manager versions prior to 11.4

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.