CVE-2018-17560: XSS
Published Jun 28, 2019
·Updated
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
Affected Software
1 affected component
Teamwire Teamwire>=1.5.1<1.9.0
Event History
Jun 28, 2019
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17560?
CVE-2018-17560 is considered a critical vulnerability due to its potential for stored XSS attacks.
2
How do I fix CVE-2018-17560?
To fix CVE-2018-17560, upgrade the Grouptime Teamwire Client to version 1.9.0 or later.
3
What software versions are vulnerable to CVE-2018-17560?
All versions of the Grouptime Teamwire Client prior to 1.9.0 are vulnerable to CVE-2018-17560.
4
Can CVE-2018-17560 be exploited remotely?
Yes, CVE-2018-17560 can be exploited remotely through the affected admin interface.
5
What impact does CVE-2018-17560 have on affected systems?
Exploitation of CVE-2018-17560 can lead to stored XSS vulnerabilities, allowing attackers to execute malicious scripts in the context of authenticated users.