First published: Wed Sep 19 2018(Updated: )
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opmantek Open-AudIT | =2.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-16607.
The title of the vulnerability is Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2…
The severity of CVE-2018-16607 is medium with a CVSS base score of 5.4.
The affected software for CVE-2018-16607 is Open-AudIT Professional edition version 2.2.7.
Remote attackers can exploit CVE-2018-16607 by injecting arbitrary web script via the Orgs name field on the Orgs Page in Open-AudIT Professional edition 2.2.7.