Vulnerability Description
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Colorqube 8580 Firmware | - |
| Xerox | Colorqube 8580 | - |
Related Weaknesses (CWE)
References
- https://ysec.ch/?p=94ExploitThird Party Advisory
- https://ysec.ch/?p=94ExploitThird Party Advisory
FAQ
What is CVE-2018-15530?
CVE-2018-15530 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
How severe is CVE-2018-15530?
CVE-2018-15530 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15530?
Check the references section above for vendor advisories and patch information. Affected products include: Xerox Colorqube 8580 Firmware, Xerox Colorqube 8580.