CVE-2018-14503: XSS
Published Aug 10, 2018
·Updated
Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
Affected Software
1 affected component
Coremail Coremail XT=3.0
Event History
Aug 10, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14503?
CVE-2018-14503 has a medium severity level due to its impact on web application security.
2
How do I fix CVE-2018-14503?
To fix CVE-2018-14503, validate and sanitize the 'sid' parameter input to prevent XSS attacks.
3
What is the impact of CVE-2018-14503 on users?
CVE-2018-14503 allows remote attackers to execute arbitrary scripts in the context of another user's session, potentially compromising user data.
4
Is CVE-2018-14503 exploitable remotely?
Yes, CVE-2018-14503 is exploitable remotely, allowing attackers to target vulnerable applications accessible via the internet.
5
What versions of Coremail are affected by CVE-2018-14503?
CVE-2018-14503 affects Coremail XT version 3.0 specifically.