Medium severity6.1OSV Advisory· Published Jul 9, 2018· Updated Jun 17, 2026
CVE-2018-1000611
CVE-2018-1000611
Description
SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can result in Allows an attacker to inject arbitrary web scripts or HTML into help and login pages. This attack appear to be exploitable via the victim opening a specially crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 5.7.0, 5.7.1, 5.7.3
- Range: >=5.7.0, <=5.7.3
Patches
Vulnerability mechanics
References
1- github.com/OpenConext/OpenConext-engineblock/pull/563/filesnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.