Record summary

CVE-2018-10230 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMZend Server <9.13 - Cross-Site ScriptingCVSS 6.1

Zend Server before version 9.13 is vulnerable to cross-site scripting via the debug_host parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade Zend Server to version 9.13 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsmarcos_iaf
Template tagscvecve2018xsszendvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:zend:zend_server:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:zend:zend_server"

Source: ProjectDiscovery

References

3