CVE-2018-8846: XSS
Published Sep 26, 2018
·Updated
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is then served to other users.
Affected Software
1 affected component
Philips E-alert Firmware<=r2.1
Event History
Sep 26, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-8846.
2
What is the severity of CVE-2018-8846?
The severity of CVE-2018-8846 is medium (6.1).
3
What is affected by CVE-2018-8846?
Philips e-Alert Unit (non-medical device) Version R2.1 and prior.
4
What is the impact of CVE-2018-8846?
The impact of CVE-2018-8846 is that user-controllable input can be mistakenly placed in the output web page served to other users.
5
How can I fix CVE-2018-8846?
To fix CVE-2018-8846, you should update to a version later than R2.1 of Philips e-Alert Unit software.