Description
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-3579 | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application. |
References
| Link | Providers |
|---|---|
| http://seclists.org/fulldisclosure/2018/May/70 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:10:14.660Z
Reserved: 2018-05-29T00:00:00.000Z
Link: CVE-2018-11552
No data.
Status : Modified
Published: 2018-06-01T17:29:00.330
Modified: 2024-11-21T03:43:35.897
Link: CVE-2018-11552
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD