CVE-2018-20858: XSS
Recommender before 1.3.1 allows XSS. It is possible for a learner to craft a fake resource to recommender, that includes script which could possibly steal credentials from staff if they are lured into viewing the recommended resource.
Other sources
Recommender before 2018-07-18 allows XSS.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20858?
CVE-2018-20858 is classified as a moderate severity vulnerability due to its potential impact on user security through XSS.
How do I fix CVE-2018-20858?
To fix CVE-2018-20858, upgrade the Recommender software to version 1.3.1 or later.
Which versions are affected by CVE-2018-20858?
CVE-2018-20858 affects all versions of Recommender before 1.3.1.
What type of vulnerability is CVE-2018-20858?
CVE-2018-20858 is an XSS vulnerability that allows an attacker to inject malicious scripts.
What are the potential risks associated with CVE-2018-20858?
The potential risks of CVE-2018-20858 include credential theft and unauthorized access if users view crafted resources.