CVE-2018-11343: XSS
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11343.
What is the severity of CVE-2018-11343?
The severity of CVE-2018-11343 is medium with a severity value of 5.4.
What is the affected software for CVE-2018-11343?
The affected software for CVE-2018-11343 is ASUSTOR SoundsGood application.
How does CVE-2018-11343 work?
CVE-2018-11343 allows attackers to store cross-site scripting payloads via the 'playlist' POST parameter in playlistmanger.cgi in the ASUSTOR SoundsGood application.
Are there any references for CVE-2018-11343?
Yes, you can find references for CVE-2018-11343 at the following links: [link1](http://seclists.org/fulldisclosure/2018/May/2), [link2](https://github.com/mefulton/asustorexploit), and [link3](https://www.purehacking.com/blog/matthew-fulton/back-to-the-future-asustor-web-exploitation).