CVE-2018-20369: XSS
Published Dec 23, 2018
·Updated
Barracuda Message Archiver 2018 has XSS in the errormsg exception-handling value for the ldapuser parameter to the cgi-mod/ldaploadentry.cgi module. The injection point of the issue is the AddUpdate module.
Affected Software
1 affected component
Barracuda Message Archiver=2018
Event History
Dec 23, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-20369?
CVE-2018-20369 is a vulnerability in Barracuda Message Archiver 2018 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2018-20369?
CVE-2018-20369 has a severity score of 6.1, which is considered medium.
3
How does CVE-2018-20369 work?
CVE-2018-20369 exploits the error_msg exception-handling value for the ldap_user parameter in the cgi-mod/ldap_load_entry.cgi module, allowing for XSS attacks.
4
What software is affected by CVE-2018-20369?
Barracuda Message Archiver 2018 is affected by CVE-2018-20369.
5
How can I fix CVE-2018-20369?
To fix CVE-2018-20369, it is recommended to apply the necessary security patches or updates provided by Barracuda Networks.