CVE-2018-12353: XSS
Published Jun 13, 2018
·Updated
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
Affected Software
1 affected component
Knowage-suite Knowage=6.1.1
Event History
Jun 13, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12353?
The severity of CVE-2018-12353 is medium with a value of 6.1.
2
How does CVE-2018-12353 affect Knowage (formerly SpagoBI) 6.1.1?
CVE-2018-12353 allows XSS attacks via the name field in the "Business Model's Catalogue" catalogue.
3
What software versions are affected by CVE-2018-12353?
CVE-2018-12353 affects Knowage (formerly SpagoBI) 6.1.1.
4
How can I fix CVE-2018-12353?
To fix CVE-2018-12353, it is recommended to upgrade Knowage (formerly SpagoBI) to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2018-12353?
More information about CVE-2018-12353 can be found at the following link: [link](https://medium.com/stolabs/security-issue-on-knowage-spagobi-ec539a68e55).