CVE-2018-15703: XSS
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15703?
CVE-2018-15703 is considered a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2018-15703?
To mitigate CVE-2018-15703, upgrade to a version of Advantech WebAccess that is above 8.3.2 to avoid the reflected XSS vulnerabilities.
What types of attacks are possible with CVE-2018-15703?
CVE-2018-15703 allows remote unauthenticated attackers to perform reflected cross-site scripting attacks.
What software is affected by CVE-2018-15703?
CVE-2018-15703 affects Advantech WebAccess versions 8.3.2 and below.
Can CVE-2018-15703 be exploited without authentication?
Yes, CVE-2018-15703 can be exploited by unauthenticated attackers.