VYPR
Medium severity6.1OSV Advisory· Published Jun 26, 2018· Updated Jun 17, 2026

CVE-2018-1000528

CVE-2018-1000528

Description

GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to have been fixed in after commit 56070d6289d47ba3f5918885954dcceb75606001.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Range: 2.7.5, 2.7.5.1, 2.7.5.2
  • Gonicus/GOsa2 versions
    cpe:2.3:a:gonicus:gosa:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gonicus:gosa:-:*:*:*:*:*:*:*
    • (no CPE)
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.