CVE-2018-13065: XSS
Published Jul 3, 2018
·Updated
DISPUTED ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured.
Affected Software
2 affected components
Trustwave ModSecurity=3.0.0
OWASP Modsecurity=3.0.0
Event History
Jul 3, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Disputed
12:29 PM
Data Sourced
via NVD·12:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-13065?
CVE-2018-13065 is a vulnerability in ModSecurity 3.0.0 that allows XSS attacks through the onerror attribute of an IMG element.
2
What is the severity of CVE-2018-13065?
The severity of CVE-2018-13065 is medium (6.1).
3
What software is affected by CVE-2018-13065?
ModSecurity 3.0.0 is affected by CVE-2018-13065.
4
Are there any known exploits for CVE-2018-13065?
Yes, there are known exploits for CVE-2018-13065.
5
How can I prevent XSS attacks through the onerror attribute of an IMG element in ModSecurity 3.0.0?
To prevent XSS attacks through the onerror attribute of an IMG element in ModSecurity 3.0.0, ensure that a Core Rule Set is configured.