Vulnerability Description
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yunohost | Yunohost | >= 2.7.2, <= 2.7.14 |
Related Weaknesses (CWE)
References
- https://www.bishopfox.com/news/2018/10/yunohost-2-7-2-to-2-7-14-multiple-vulneraExploitThird Party Advisory
- https://www.bishopfox.com/news/2018/10/yunohost-2-7-2-to-2-7-14-multiple-vulneraExploitThird Party Advisory
FAQ
What is CVE-2018-11348?
CVE-2018-11348 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to ...
How severe is CVE-2018-11348?
CVE-2018-11348 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11348?
Check the references section above for vendor advisories and patch information. Affected products include: Yunohost Yunohost.