First published: Fri Jun 28 2019(Updated: )
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teamwire | >=1.5.1<1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17560 is considered a critical vulnerability due to its potential for stored XSS attacks.
To fix CVE-2018-17560, upgrade the Grouptime Teamwire Client to version 1.9.0 or later.
All versions of the Grouptime Teamwire Client prior to 1.9.0 are vulnerable to CVE-2018-17560.
Yes, CVE-2018-17560 can be exploited remotely through the affected admin interface.
Exploitation of CVE-2018-17560 can lead to stored XSS vulnerabilities, allowing attackers to execute malicious scripts in the context of authenticated users.