CVE-2017-12544
HPE System Management - Cross-Site Scripting
Record summary
CVE-2017-12544 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
System Management Homepage for Windows and LinuxBrowse Hewlett Packard Enterprise / System Management Homepage for Windows and Linux | CVE List | prior to 7.6.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMHPE System Management - Cross-Site ScriptingCVSS 5.4
HPE System Management contains a cross-site scripting vulnerability which allows an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser.
Remediation
Apply the latest security patches or updates provided by HPE to fix the XSS vulnerability in the System Management software.
Source: ProjectDiscovery