First published: Fri Jul 06 2018(Updated: )
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opmantek Open-AudIT | <2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11124 is a cross-site scripting (XSS) vulnerability in the Attributes functionality in Open-AudIT Community edition before 2.2.2.
The CVE-2018-11124 vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
CVE-2018-11124 has a severity rating of medium with a score of 5.4.
Open-AudIT Community edition before version 2.2.2 is affected by CVE-2018-11124.
To fix the CVE-2018-11124 vulnerability, upgrade to Open-AudIT Community edition version 2.2.2 or later.