CVE-2018-12305: XSS
Published Dec 4, 2018
·Updated
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
Affected Software
1 affected component
ASUSTOR Data Master=3.1.1
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting vulnerability?
The vulnerability ID for this cross-site scripting vulnerability is CVE-2018-12305.
2
What is the severity of CVE-2018-12305?
The severity of CVE-2018-12305 is medium with a CVSS score of 6.1.
3
How does the cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allow attackers to execute JavaScript?
The cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
4
Which ASUSTOR ADM version is affected by the CVE-2018-12305 vulnerability?
ASUSTOR ADM version 3.1.1 is affected by the CVE-2018-12305 vulnerability.
5
Is there any known fix for CVE-2018-12305?
A fix for CVE-2018-12305 may be available from ASUSTOR. It is recommended to update to the latest version of ASUSTOR ADM to mitigate this vulnerability.