CVE-2018-15312: XSS
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15312?
The severity of CVE-2018-15312 is classified as high due to the potential for reflected Cross-Site Scripting attacks.
How do I fix CVE-2018-15312?
To mitigate CVE-2018-15312, apply the recommended patches provided by F5 for affected versions of BIG-IP.
Who is affected by CVE-2018-15312?
CVE-2018-15312 affects F5 BIG-IP versions 12.1.0-12.1.3.6 and 13.0.0-13.1.1.1.
What types of attacks can CVE-2018-15312 enable?
CVE-2018-15312 can enable attackers to execute arbitrary JavaScript code in the context of the logged-in user's session.
Is user authentication required to exploit CVE-2018-15312?
Yes, CVE-2018-15312 requires an authenticated user to exploit the reflected Cross-Site Scripting vulnerability.