The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.
References
Configurations
History
21 Nov 2024, 04:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-566773.pdf - | |
References | () https://drive.google.com/file/d/18BaBzGcjWAfJyZ_phWEVerYmmLB-vxF-/view?usp=sharing - Vendor Advisory |
Information
Published : 2018-05-02 21:29
Updated : 2024-11-21 04:14
NVD link : CVE-2018-8900
Mitre link : CVE-2018-8900
CVE.ORG link : CVE-2018-8900
JSON object : View
Products Affected
gemalto
- sentinel_ldk_rte
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')