CVE-2018-12311: XSS
Published Dec 4, 2018
·Updated
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
Affected Software
2 affected components
ASUSTOR Data Master=3.1.1
ASUSTOR As602t
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-12311?
CVE-2018-12311 is a cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1.
2
How does CVE-2018-12311 impact ASUSTOR ADM version 3.1.1?
CVE-2018-12311 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
3
What is the severity of CVE-2018-12311?
The severity of CVE-2018-12311 is 5.4 (Medium).
4
Which software versions are affected by CVE-2018-12311?
ASUSTOR ADM version 3.1.1 is affected by CVE-2018-12311.
5
How can I fix CVE-2018-12311?
To fix CVE-2018-12311, update ASUSTOR ADM to a version that is not vulnerable.