nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-18570 CVE-2018-18570
MEDIUMNuclei
Planon <Live Build 41 - Cross-Site Scripting
Record summary
CVE-2018-18570 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Planon before Live Build 41 has XSS.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMPlanon <Live Build 41 - Cross-Site ScriptingCVSS 6.1
Planon before Live Build 41 is vulnerable to cross-site scripting.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest patch or upgrade to a non-vulnerable version of Planon Live Build.
WeaknessesCWE-79
Authorsemadshanab
Template tagscvecve2018xssplanonplanonsoftwarevuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:planonsoftware:planon:*:*:*:*:*:*:*:*
https://www2.deloitte.com/de/de/pages/risk/articles/planon-cross-site-scripting.html https://nvd.nist.gov/vuln/detail/CVE-2018-18570 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2www2.deloitte.com
https://www2.deloitte.com/de/de/pages/risk/articles/planon-cross-site-scripting.html