First published: Thu May 02 2019(Updated: )
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Buffalo Open Xdmod | <=7.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16960 is a vulnerability in Open XDMoD versions up to 7.5.0 that allows for reflected cross-site scripting (XSS) attacks.
CVE-2018-16960 affects Open XDMoD versions up to 7.5.0, allowing attackers to perform reflected XSS attacks.
CVE-2018-16960 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2018-16960, it is recommended to update to a version of Open XDMoD that is not affected by the vulnerability.
Cross-site scripting (XSS) is a type of web vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.