Vulnerability Description
userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log page.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/44871
- https://www.vulncheck.com/advisories/userspice-cross-site-scripting-via-x-forwar
FAQ
What is CVE-2018-25349?
CVE-2018-25349 is a vulnerability with a CVSS score of 6.1 (MEDIUM). userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the bac...
How severe is CVE-2018-25349?
CVE-2018-25349 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25349?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.