CVE-2018-0697: XSS
Published Nov 15, 2018
·Updated
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Metabase<=0.29.3
Event History
Nov 15, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0697?
The severity of CVE-2018-0697 is medium with a CVSS score of 6.1.
2
What software versions are affected by CVE-2018-0697?
Metabase version 0.29.3 and earlier are affected by CVE-2018-0697.
3
How can remote attackers exploit CVE-2018-0697?
Remote attackers can exploit CVE-2018-0697 by injecting arbitrary web script or HTML via unspecified vectors.
4
Are there any references for CVE-2018-0697?
Yes, you can find references for CVE-2018-0697 at the following URLs: http://jvn.jp/en/jp/JVN14323043/index.html and https://metabase.com/
5
What Common Weakness Enumeration (CWE) category does CVE-2018-0697 belong to?
CVE-2018-0697 belongs to the CWE category 79 which is Cross-Site Scripting (XSS).