CVE-2018-18282: XSS
Published Oct 12, 2018
·Updated
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /error page.
Affected Software
2 affected components
ZEIT Next.js=7.0.0
ZEIT Next.js=7.0.1
Event History
Oct 12, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18282?
CVE-2018-18282 has been categorized as a high severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-18282?
To fix CVE-2018-18282, upgrade Next.js to version 7.0.2 or later.
3
What types of pages are affected by CVE-2018-18282?
CVE-2018-18282 affects the 404 and 500 error pages within Next.js versions 7.0.0 and 7.0.1.
4
Who is affected by CVE-2018-18282?
Anyone using Next.js versions 7.0.0 or 7.0.1 is affected by CVE-2018-18282.
5
What is the nature of the vulnerability in CVE-2018-18282?
CVE-2018-18282 is a cross-site scripting (XSS) vulnerability that can lead to the execution of malicious scripts.