Record summary

CVE-2018-8006 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List5.0.0 to 5.15.5affected

org.apache.activemq:activemq-web-console

Browse Maven / org.apache.activemq:activemq-web-console
GitHub Advisory5.0.0 to < 5.15.6 · Fixed in 5.15.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMApache ActiveMQ <=5.15.5 - Cross-Site ScriptingCVSS 6.1

Apache ActiveMQ versions 5.0.0 to 5.15.5 are vulnerable to cross-site scripting via the web based administration console on the queue.jsp page. The root cause of this issue is improper data filtering of the QueueFilter parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade Apache ActiveMQ to a version higher than 5.15.5 or apply the necessary patches provided by the vendor.

WeaknessesCWE-79
Authorspdteam
Template tagscve2018cveapacheactivemqxssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:apache:activemq"
Shodan: product:"activemq openwire transport"

Source: ProjectDiscovery

References

Showing 12 of 24