CVE-2018-6291: XSS
Published Feb 6, 2018
·Updated
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
Affected Software
1 affected component
Kaspersky Secure Mail Gateway=1.1
Event History
Feb 6, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6291?
CVE-2018-6291 has a medium severity rating due to its Cross-Site Scripting vulnerability.
2
How do I fix CVE-2018-6291?
To fix CVE-2018-6291, update Kaspersky Secure Mail Gateway to a patched version provided by Kaspersky.
3
What types of attacks can CVE-2018-6291 facilitate?
CVE-2018-6291 can facilitate Cross-Site Scripting attacks, potentially allowing an attacker to execute malicious scripts.
4
Is CVE-2018-6291 present in versions of Kaspersky Secure Mail Gateway other than 1.1?
No, CVE-2018-6291 specifically affects Kaspersky Secure Mail Gateway version 1.1.
5
What are the implications of CVE-2018-6291 for users?
Users affected by CVE-2018-6291 are at risk of session hijacking and data theft due to the Cross-Site Scripting vulnerability.