CVE-2018-9155
MEDIUMOpen-AudIT Professional 2.1.1 - Stored Cross-Site Scripting via Component Name Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-9155. PoCs published by Tejesh Kolisetty.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in Open-AudIT Professional 2.1.1. It details the steps to exploit the vulnerability in multiple instances, such as creating attributes or users with malicious scripts.
Description
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the attributes/create URI).
Exploits (1)
This is a writeup describing a stored XSS vulnerability in Open-AudIT Professional 2.1.1. It details the steps to exploit the vulnerability in multiple instances, such as creating attributes or users with malicious scripts.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N