CVE-2024-38318: IBM Aspera Shares HTML injection
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM Aspera Shares is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38318?
The severity of CVE-2024-38318 is classified as medium, indicating a moderate risk of exploitation.
How do I fix CVE-2024-38318?
To fix CVE-2024-38318, upgrade IBM Aspera Shares to version 1.10.0 PL7 or later.
What does CVE-2024-38318 vulnerability entail?
CVE-2024-38318 is an HTML injection vulnerability that allows a remote attacker to execute malicious HTML code in the victim's browser.
Which versions of IBM Aspera Shares are affected by CVE-2024-38318?
Versions 1.9.0 through 1.10.0 PL6 of IBM Aspera Shares are affected by CVE-2024-38318.
Can CVE-2024-38318 be exploited remotely?
Yes, CVE-2024-38318 can be exploited remotely by an attacker injecting malicious HTML code.