First published: Tue Aug 07 2018(Updated: )
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thinksaas | <=2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15130 is classified as a high severity vulnerability due to its potential to enable cross-site scripting (XSS) attacks.
To fix CVE-2018-15130, update ThinkSAAS to version 2.7 or later to ensure the XSS vulnerability is patched.
CVE-2018-15130 affects ThinkSAAS versions up to and including 2.6.
CVE-2018-15130 is identified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2018-15130 can be exploited remotely by an attacker through a maliciously crafted request to the affected parameter.