CVE-2012-6369: XSS
Published Dec 28, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action.
Affected Software
1 affected component
1Password 1Password=3.9.9
Event History
Dec 28, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6369?
CVE-2012-6369 is classified as a medium severity vulnerability due to its potential to allow XSS attacks.
2
How do I fix CVE-2012-6369?
To fix CVE-2012-6369, upgrade to a later version of 1Password that addresses this vulnerability.
3
What type of vulnerability is CVE-2012-6369?
CVE-2012-6369 is a cross-site scripting (XSS) vulnerability.
4
Which software is affected by CVE-2012-6369?
CVE-2012-6369 specifically affects AgileBits 1Password version 3.9.9.
5
Can CVE-2012-6369 be exploited remotely?
Yes, CVE-2012-6369 can be exploited remotely by injecting scripts via a crafted User-Agent HTTP header.