Cross-Site Scripting Vulnerability in Philips e-Alert Unit Software
CVE-2018-8846

6.1MEDIUM

Key Information:

Vendor
Philips
Vendor
CVE Published:
26 September 2018

Summary

The Philips e-Alert Unit software prior to version R2.1 is susceptible to a cross-site scripting (XSS) vulnerability. This issue arises due to improper neutralization of user-controllable input, allowing malicious scripts to be embedded in web pages served to users. When exploited, this vulnerability can lead to unauthorized actions being performed on behalf of users, risking data integrity and user sessions. Mitigation measures should be applied to sanitize and validate user input effectively to protect users from such security risks.

Affected Version(s)

e-Alert Unit (non-medical device) R2.1 and prior

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.