CVE-2018-12297: XSS
Published May 13, 2019
·Updated
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
Affected Software
1 affected component
Seagate NAS OS=4.3.15.1
Event History
May 13, 2019
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12297?
CVE-2018-12297 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2018-12297?
To fix CVE-2018-12297, upgrade your Seagate NAS OS to a version newer than 4.3.15.1 that addresses this vulnerability.
3
What is the impact of CVE-2018-12297?
The impact of CVE-2018-12297 allows attackers to execute arbitrary JavaScript through API error pages on affected Seagate NAS devices.
4
Which versions are affected by CVE-2018-12297?
CVE-2018-12297 affects Seagate NAS OS version 4.3.15.1.
5
Can CVE-2018-12297 be exploited remotely?
Yes, CVE-2018-12297 can be exploited remotely, enabling attackers to manipulate users visiting affected error pages.