Cross-Site Scripting Vulnerability in Philips e-Alert Unit Software
CVE-2018-8846
6.1MEDIUM
Key Information:
- Vendor
- Philips
- Vendor
- CVE Published:
- 26 September 2018
Summary
The Philips e-Alert Unit software prior to version R2.1 is susceptible to a cross-site scripting (XSS) vulnerability. This issue arises due to improper neutralization of user-controllable input, allowing malicious scripts to be embedded in web pages served to users. When exploited, this vulnerability can lead to unauthorized actions being performed on behalf of users, risking data integrity and user sessions. Mitigation measures should be applied to sanitize and validate user input effectively to protect users from such security risks.
Affected Version(s)
e-Alert Unit (non-medical device) R2.1 and prior
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved