CVE-2018-16607: XSS
Published Sep 19, 2018
·Updated
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
Affected Software
1 affected component
Opmantek Open-AudIT=2.2.7
Event History
Sep 19, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-16607.
2
What is the title of the vulnerability?
The title of the vulnerability is Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2…
3
What is the severity of CVE-2018-16607?
The severity of CVE-2018-16607 is medium with a CVSS base score of 5.4.
4
What is the affected software for CVE-2018-16607?
The affected software for CVE-2018-16607 is Open-AudIT Professional edition version 2.2.7.
5
How can remote attackers exploit CVE-2018-16607?
Remote attackers can exploit CVE-2018-16607 by injecting arbitrary web script via the Orgs name field on the Orgs Page in Open-AudIT Professional edition 2.2.7.