CVE-2018-12319: XSS
Published Dec 4, 2018
·Updated
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
Affected Software
2 affected components
ASUSTOR Data Master=3.1.1
ASUSTOR As602t
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-12319?
CVE-2018-12319 is a denial-of-service vulnerability in the login page of ASUSTOR ADM 3.1.1, which allows attackers to prevent users from signing in by placing malformed text in the title.
2
How severe is CVE-2018-12319?
CVE-2018-12319 has a severity rating of 7.5, which is considered high.
3
Which software versions are affected by CVE-2018-12319?
ASUSTOR ADM 3.1.1 is affected by CVE-2018-12319.
4
How can attackers exploit CVE-2018-12319?
Attackers can exploit CVE-2018-12319 by placing malformed text in the title of the login page, causing a denial-of-service.
5
Is the Asustor As602t affected by CVE-2018-12319?
No, the Asustor As602t is not vulnerable to CVE-2018-12319.