CVE-2018-12658: XSS
Published Jun 22, 2018
·Updated
Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stocktake/index.php?keywords= URI.
Affected Software
1 affected component
Slims Project Slims=8.3.1
Event History
Jun 22, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12658?
The severity of CVE-2018-12658 is classified as medium due to its potential to allow reflected cross-site scripting attacks.
2
How do I fix CVE-2018-12658?
To fix CVE-2018-12658, update SLiMS to version 8.3.2 or later, which addresses the reflected XSS vulnerability.
3
What versions of SLiMS are affected by CVE-2018-12658?
CVE-2018-12658 affects SLiMS version 8.3.1 specifically.
4
What type of attack is enabled by CVE-2018-12658?
CVE-2018-12658 enables a reflected Cross-Site Scripting (XSS) attack which can compromise user data.
5
Where does the vulnerability CVE-2018-12658 exist in the SLiMS application?
The vulnerability CVE-2018-12658 exists in the Stock Take module at admin/modules/stock_take/index.php?keywords=.