Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-6014
HistoryJan 23, 2018 - 12:29 a.m.

Cross site scripting

2018-01-2300:29:00
PRIOn knowledge base
www.prio-n.com
7

6.1 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.6%

Subsonic v6.1.3 has an insecure allow-access-from domain=“*” Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a web site loaded with a SWF file created specifically to steal user data.

CPENameOperatorVersion
subsoniceq6.1.3

6.1 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.6%

Related for PRION:CVE-2018-6014