CVE-2018-1541

Severity
5.4MEDIUM
EPSS
0.2%
top 64.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 24
Latest updateMay 13

Description

IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5ibm/websphere_commerce_enterpriseV7, V8, V9+2
NVDibm/websphere_commerce8.0.0.08.0.0.19+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ch82-w798-ww9r: IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting2022-05-13
CVEList
CVE-2018-1541: IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting2018-10-24
CVE-2018-1541 (MEDIUM CVSS 5.4) | IBM WebSphere Commerce Enterprise V | cvebase.io