First published: Wed Dec 12 2018(Updated: )
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | <9.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-17952 is classified as medium, indicating it can be exploited under certain conditions.
To fix CVE-2018-17952, update eDirectory to version 9.1 SP2 or later.
Versions of eDirectory prior to 9.1 SP2 are vulnerable to CVE-2018-17952.
CVE-2018-17952 is a cross site scripting (XSS) vulnerability.
Yes, CVE-2018-17952 can be exploited remotely if the attacker can inject malicious scripts into the application.