CVE-2018-16778: XSS
Published Dec 21, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field).
Affected Software
1 affected component
Jenzabar Jenzabar>=8.2.1<=9.2.0
Event History
Dec 21, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16778?
CVE-2018-16778 is a cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0.
2
Is the Jenzabar software affected by CVE-2018-16778?
Yes, Jenzabar v8.2.1 through 9.2.0 is affected by the CVE-2018-16778 vulnerability.
3
How does CVE-2018-16778 work?
CVE-2018-16778 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field).
4
What is the severity of CVE-2018-16778?
CVE-2018-16778 has a severity rating of medium (6.1).
5
How can I fix CVE-2018-16778?
To fix CVE-2018-16778, update your Jenzabar software to a version higher than 9.2.0.