CVE-2018-8900

The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gemalto:sentinel_ldk_rte:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-566773.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-566773.pdf -
References () https://drive.google.com/file/d/18BaBzGcjWAfJyZ_phWEVerYmmLB-vxF-/view?usp=sharing - Vendor Advisory () https://drive.google.com/file/d/18BaBzGcjWAfJyZ_phWEVerYmmLB-vxF-/view?usp=sharing - Vendor Advisory

Information

Published : 2018-05-02 21:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-8900

Mitre link : CVE-2018-8900

CVE.ORG link : CVE-2018-8900


JSON object : View

Products Affected

gemalto

  • sentinel_ldk_rte
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')