First published: Wed Oct 31 2018(Updated: )
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess | =8.3.1 | |
Advantech WebAccess | =8.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15707 is a vulnerability in Advantech WebAccess 8.3.1 and 8.3.2 that allows for cross-site scripting (XSS) attacks.
CVE-2018-15707 affects Advantech WebAccess 8.3.1 and 8.3.2 by enabling attackers to perform cross-site scripting attacks, which can lead to credential disclosure and other security risks.
CVE-2018-15707 has a severity score of 5.4 (medium).
To fix CVE-2018-15707, it is recommended to update Advantech WebAccess to a version that is not affected by this vulnerability.
Additional information about CVE-2018-15707 can be found at the following references: [Exploit-DB](https://www.exploit-db.com/exploits/45774/) and [Tenable Research Advisory](https://www.tenable.com/security/research/tra-2018-35).