CVE-2018-18548: XSS
Published Oct 24, 2018
·Updated
Ajenti through v1.2.23.13 has a Cross-site Scripting (XSS) vulnerability via a filename that is mishandled in File Manager.
Other sources
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
Affected Software
2 affected components
pip/ajenti<=1.2.23.13
Ajenti ajenticp<=1.2.23.13
Event History
Oct 24, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-18548?
CVE-2018-18548 is classified as a medium severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2018-18548?
To fix CVE-2018-18548, update Ajenti to version 1.2.23.14 or later, which addresses this vulnerability.
3
What type of vulnerability is CVE-2018-18548?
CVE-2018-18548 is a Cross-site Scripting (XSS) vulnerability found in the Ajenti File Manager.
4
In which versions is CVE-2018-18548 present?
CVE-2018-18548 affects Ajenti versions up to and including 1.2.23.13.
5
How can CVE-2018-18548 be exploited?
CVE-2018-18548 can be exploited by an attacker through a carefully crafted filename that triggers XSS in the File Manager.