CVE-2018-12310: XSS
Published Dec 4, 2018
·Updated
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.
Affected Software
2 affected components
ASUSTOR Data Master=3.1.1
ASUSTOR As602t
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1?
The vulnerability ID for the Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 is CVE-2018-12310.
2
What is the severity of CVE-2018-12310?
The severity of CVE-2018-12310 is medium with a CVSS score of 5.4.
3
How does CVE-2018-12310 affect ASUSTOR ADM version 3.1.1?
CVE-2018-12310 allows attackers to execute JavaScript via the System Announcement feature in the Login page of ASUSTOR ADM version 3.1.1.
4
What is the affected software for CVE-2018-12310?
The affected software for CVE-2018-12310 is ASUSTOR Data Master version 3.1.1.
5
Is Asustor As602t affected by CVE-2018-12310?
No, Asustor As602t is not affected by CVE-2018-12310.
6
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-12310?
The Common Weakness Enumeration (CWE) ID for CVE-2018-12310 is CWE-79.