Unrated severityNVD Advisory· Published Oct 19, 2018· Updated Sep 17, 2024
CVE-2018-15312
CVE-2018-15312
Description
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.
Affected products
2- F5, Inc./Big Ip (ltm, Aam, Afm, Analytics, Apm, Asm, DNS, Edge Gateway, Fps, Gtm, Link Controller, Pem, Webaccelerator)cpe-rescueRange: 13.0.0-13.1.1.1
Patches
Vulnerability mechanics
References
2- www.securitytracker.com/id/1041932mitrevdb-entryx_refsource_SECTRACK
- support.f5.com/csp/article/K44462254mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.