CVE-2018-15574

An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability."
Configurations

Configuration 1 (hide)

cpe:2.3:a:reprisesoftware:reprise_license_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:51

Type Values Removed Values Added
References () https://bittherapy.net/rce-with-arbitrary-file-write-and-xss-in-reprise-license-manager/ - Exploit, Third Party Advisory () https://bittherapy.net/rce-with-arbitrary-file-write-and-xss-in-reprise-license-manager/ - Exploit, Third Party Advisory
References () https://reprisesoftware.com/docs/whats-new.html - () https://reprisesoftware.com/docs/whats-new.html -

29 May 2024, 19:15

Type Values Removed Values Added
Summary (en) An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability. (en) An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability."
References
  • () https://reprisesoftware.com/docs/whats-new.html -

07 Nov 2023, 02:53

Type Values Removed Values Added
Summary ** DISPUTED ** An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability." An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability.

Information

Published : 2018-08-20 02:29

Updated : 2024-11-21 03:51


NVD link : CVE-2018-15574

Mitre link : CVE-2018-15574

CVE.ORG link : CVE-2018-15574


JSON object : View

Products Affected

reprisesoftware

  • reprise_license_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')