CVE-2018-12299: XSS
Published May 13, 2019
·Updated
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
Affected Software
1 affected component
Seagate NAS OS=4.3.15.1
Event History
May 13, 2019
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12299?
CVE-2018-12299 has a medium severity rating due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2018-12299?
To fix CVE-2018-12299, ensure you upgrade to Seagate NAS OS version 4.3.15.2 or later.
3
What type of vulnerability is CVE-2018-12299?
CVE-2018-12299 is a cross-site scripting (XSS) vulnerability affecting filebrowser functionality.
4
Who is affected by CVE-2018-12299?
CVE-2018-12299 affects users of Seagate NAS OS version 4.3.15.1.
5
Can CVE-2018-12299 allow remote code execution?
While CVE-2018-12299 primarily pertains to XSS, it can indirectly lead to unwanted script execution if exploited.