nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10230 CVE-2018-10230
MEDIUMNuclei
Zend Server <9.13 - Cross-Site Scripting
Record summary
CVE-2018-10230 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMZend Server <9.13 - Cross-Site ScriptingCVSS 6.1
Zend Server before version 9.13 is vulnerable to cross-site scripting via the debug_host parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade Zend Server to version 9.13 or later to mitigate this vulnerability.
WeaknessesCWE-79
Authorsmarcos_iaf
Template tagscvecve2018xsszendvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:zend:zend_server:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:zend:zend_server"
https://www.synacktiv.com/ressources/zend_server_9_1_3_xss.pdf https://www.zend.com/en/products/server/release-notes https://nvd.nist.gov/vuln/detail/CVE-2018-10230 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3synacktiv.com
https://www.synacktiv.com/ressources/zend_server_9_1_3_xss.pdf zend.comConfirmation
https://www.zend.com/en/products/server/release-notes