Vulnerability Description
Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adbglobal | Epicentro | 7.3.2 |
Related Weaknesses (CWE)
References
- https://fschallock.wordpress.com/2018/10/08/cve-2018-7633-script-injection-in-thExploitThird Party Advisory
- https://fschallock.wordpress.com/2018/10/08/cve-2018-7633-script-injection-in-thExploitThird Party Advisory
FAQ
What is CVE-2018-7633?
CVE-2018-7633 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request.
How severe is CVE-2018-7633?
CVE-2018-7633 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-7633?
Check the references section above for vendor advisories and patch information. Affected products include: Adbglobal Epicentro.