CVE-2018-10314
MEDIUMOpen-AudIT Community 2.2.0 - Stored Cross-Site Scripting via Component Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-10314. PoCs published by Tejesh Kolisetty.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in Open-AudIT Community 2.2.0. The exploit involves injecting a script payload into the 'action' parameter during script downloads, leading to arbitrary JavaScript execution in the context of the user's browser.
Description
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in Open-AudIT Community 2.2.0. The exploit involves injecting a script payload into the 'action' parameter during script downloads, leading to arbitrary JavaScript execution in the context of the user's browser.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N