Record summary

CVE-2018-19877 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBAdiscon LogAnalyzer < 4.1.7 - Cross-Site ScriptingExploitDB exploitby Gustavo SorondoNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMAdiscon LogAnalyzer <4.1.7 - Cross-Site ScriptingCVSS 6.1

Adiscon LogAnalyzer before 4.1.7 contains a cross-site scripting vulnerability in the 'referer' parameter of the login.php file.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade Adiscon LogAnalyzer to version 4.1.7 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2018adisconxssedbvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:adiscon:loganalyzer:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3