CVE-2018-1253: Stored cross-site scripting vulnerability
RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-1253.
What is the severity of CVE-2018-1253?
The severity of CVE-2018-1253 is medium (6.1).
Which software versions are affected by CVE-2018-1253?
RSA Authentication Manager Operation Console versions 8.3 P1 and earlier are affected by CVE-2018-1253.
What is the impact of CVE-2018-1253?
A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface.
Are there any references for CVE-2018-1253?
Yes, you can find references for CVE-2018-1253 at the following links: [Link 1](http://seclists.org/fulldisclosure/2018/Jun/39), [Link 2](http://www.securityfocus.com/bid/104534), [Link 3](http://www.securitytracker.com/id/1041134).