Record summary

CVE-2017-12544 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listprior to 7.6.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMHPE System Management - Cross-Site ScriptingCVSS 5.4

HPE System Management contains a cross-site scripting vulnerability which allows an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser.

Remediation

Apply the latest security patches or updates provided by HPE to fix the XSS vulnerability in the System Management software.

WeaknessesCWE-79
Authorsdivya_mudgal
Template tagscvecve2017xsshpvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:hp:system_management_homepage:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4