CVE-2018-16096

MEDIUM

Lenovo System Management Module Firmware < 1.06 - Cross-Site Scripting in Enclosure VPD Input

Title source: llm
STIX 2.1

Description

In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/solutions/LEN-24374

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
lenovo/system_management_module_firmware < 1.06
Published Nov 27, 2018
Tracked Since Feb 18, 2026