CVE-2018-17952: XSS
Published Dec 12, 2018
·Updated
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
Affected Software
1 affected component
MicroFocus Edirectory<9.1.2
Event History
Dec 12, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-17952?
The severity of CVE-2018-17952 is classified as medium, indicating it can be exploited under certain conditions.
2
How do I fix CVE-2018-17952?
To fix CVE-2018-17952, update eDirectory to version 9.1 SP2 or later.
3
Which versions of eDirectory are vulnerable to CVE-2018-17952?
Versions of eDirectory prior to 9.1 SP2 are vulnerable to CVE-2018-17952.
4
What type of vulnerability is CVE-2018-17952?
CVE-2018-17952 is a cross site scripting (XSS) vulnerability.
5
Can CVE-2018-17952 be exploited remotely?
Yes, CVE-2018-17952 can be exploited remotely if the attacker can inject malicious scripts into the application.