Vulnerability Details CVE-2018-15699
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-15699
-
cpe:2.3:o:asustor:data_master:2.1
-
cpe:2.3:o:asustor:data_master:2.5
-
cpe:2.3:o:asustor:data_master:2.6
-
cpe:2.3:o:asustor:data_master:3.0
-
cpe:2.3:o:asustor:data_master:3.0.2.ra22
-
cpe:2.3:o:asustor:data_master:3.0.5.rdu1
-
cpe:2.3:o:asustor:data_master:3.1.0.rfq3
-
cpe:2.3:o:asustor:data_master:3.1.1
-
cpe:2.3:o:asustor:data_master:3.1.1.rgg1
-
cpe:2.3:o:asustor:data_master:3.1.2.rhg1
-
cpe:2.3:o:asustor:data_master:3.1.3.rhu2
-
cpe:2.3:o:asustor:data_master:3.1.4.rdi1
-
cpe:2.3:o:asustor:data_master:3.1.4.rid1
-
cpe:2.3:o:asustor:data_master:3.1.5