CVE-2018-14906: XSS
Published Aug 3, 2018
·Updated
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.
Affected Software
1 affected component
3CX 3cx Web Server=15.5.8801.3
Event History
Aug 3, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-14906.
2
What is the severity of CVE-2018-14906?
The severity of CVE-2018-14906 is medium, with a severity value of 6.1.
3
Which version of 3CX Web Server is affected by CVE-2018-14906?
Version 15.5.8801.3 of 3CX Web Server is affected by CVE-2018-14906.
4
What is the impact of CVE-2018-14906?
CVE-2018-14906 allows for Reflected XSS attacks on the propertyPath parameters in stack traces, potentially leading to unauthorized access or malicious actions.
5
Is there a fix available for CVE-2018-14906?
The vendor, 3CX, should release a patch or update to address this vulnerability. Please check their official website or support channels for the latest information on fixes.