Lucene search

K
ubuntucveUbuntu.comUB:CVE-2018-1000557
HistoryJun 26, 2018 - 12:00 a.m.

CVE-2018-1000557

2018-06-2600:00:00
ubuntu.com
ubuntu.com
12

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

45.0%

OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site
Scripting (XSS) vulnerability in login form and search functionality that
can result in An attacker is able to execute arbitrary (javascript) code
within a victims’ browser. This attack appear to be exploitable via Victim
must open a crafted link to the application. This vulnerability appears to
have been fixed in ocsreports 2.4.1.

Notes

Author Note
ebarretto Authentication is needed, only supported in trusted environments, see debtags

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

45.0%

Related for UB:CVE-2018-1000557