CVE-2018-15707: XSS
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15707?
CVE-2018-15707 is a vulnerability in Advantech WebAccess 8.3.1 and 8.3.2 that allows for cross-site scripting (XSS) attacks.
How does CVE-2018-15707 affect Advantech WebAccess?
CVE-2018-15707 affects Advantech WebAccess 8.3.1 and 8.3.2 by enabling attackers to perform cross-site scripting attacks, which can lead to credential disclosure and other security risks.
What is the severity of CVE-2018-15707?
CVE-2018-15707 has a severity score of 5.4 (medium).
How can I fix CVE-2018-15707?
To fix CVE-2018-15707, it is recommended to update Advantech WebAccess to a version that is not affected by this vulnerability.
Are there any additional resources for CVE-2018-15707?
Additional information about CVE-2018-15707 can be found at the following references: [Exploit-DB](https://www.exploit-db.com/exploits/45774/) and [Tenable Research Advisory](https://www.tenable.com/security/research/tra-2018-35).