A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.
2019-05-02T17:29:02.787
2024-11-21T04:42:07.950
Modified
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microfocus | open_enterprise_server | 2015.1 | Yes |
Application | microfocus | open_enterprise_server | 2018.0 | Yes |
Application | microfocus | open_enterprise_server | 2018.1 | Yes |