github.com
https://github.com/grymer/CVE/blob/master/CVE-2018-10383.md CVE-2018-10383
MEDIUMNuclei
Lantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site Scripting
Record summary
CVE-2018-10383 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMLantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site ScriptingCVSS 6.1
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
Impact
Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
Remediation
Apply the latest security patches from Lantronix or upgrade to a patched firmware version.
WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2018lantronixsecurelinxslsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:lantronix:securelinx_spider_firmware:*:*:*:*:*:*:*:*
Shodan: title:"Lantronix"
FOFA: title="Lantronix"
https://github.com/grymer/CVE/blob/master/CVE-2018-10383.md https://nvd.nist.gov/vuln/detail/CVE-2018-10383
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10383