CVE-2018-1000528: XSS
GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to have been fixed in after commit 56070d6289d47ba3f5918885954dcceb75606001.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000528?
CVE-2018-1000528 is classified as a Cross Site Scripting (XSS) vulnerability.
How do I fix CVE-2018-1000528?
To fix CVE-2018-1000528, update the GOsa package to at least version 2.7.4+reloaded3-8+deb10u2.
What software is affected by CVE-2018-1000528?
CVE-2018-1000528 affects the GOsa software, particularly versions before commit 56070d6289d47ba3f5918885954dcceb75606001.
Where can CVE-2018-1000528 be exploited?
CVE-2018-1000528 can be exploited in the change password form located at html/password.php.
What impact does CVE-2018-1000528 have?
The impact of CVE-2018-1000528 is the potential injection of arbitrary web scripts or HTML due to XSS.