Record summary

CVE-2018-10383 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMLantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site ScriptingCVSS 6.1

Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

Impact

Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.

Remediation

Apply the latest security patches from Lantronix or upgrade to a patched firmware version.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2018lantronixsecurelinxslsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:lantronix:securelinx_spider_firmware:*:*:*:*:*:*:*:*
Shodan: title:"Lantronix"
FOFA: title="Lantronix"

Source: ProjectDiscovery

References

2