CVE-2018-10934Cross-site Scripting in Redhat Jboss Enterprise Application Platform

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 38.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 14

Description

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

CVEListV5red_hat/wildfly-core7.1.6.CR1, 7.1.6.GA+1

🔴Vulnerability Details

2
GHSA
GHSA-fw7x-p3x6-x9p7: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 72022-05-14
CVEList
CVE-2018-10934: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 72019-03-27

📋Vendor Advisories

1
Red Hat
wildfly-core: Cross-site scripting (XSS) in JBoss Management Console2018-08-14

💬Community

1
Bugzilla
CVE-2018-10934 wildfly-core: Cross-site scripting (XSS) in JBoss Management Console2018-08-14
CVE-2018-10934 — Cross-site Scripting in Redhat | cvebase