Cross-Site Scripting Vulnerability in Philips e-Alert Unit Software
CVE-2018-8846
6.1MEDIUM
Key Information:
- Vendor
Philips
- Vendor
- CVE Published:
- 26 September 2018
What is CVE-2018-8846?
The Philips e-Alert Unit software prior to version R2.1 is susceptible to a cross-site scripting (XSS) vulnerability. This issue arises due to improper neutralization of user-controllable input, allowing malicious scripts to be embedded in web pages served to users. When exploited, this vulnerability can lead to unauthorized actions being performed on behalf of users, risking data integrity and user sessions. Mitigation measures should be applied to sanitize and validate user input effectively to protect users from such security risks.
Affected Version(s)
e-Alert Unit (non-medical device) R2.1 and prior