CVE Database
/

CVE-2018-12246

Back to search

CVE-2018-12246

Published: Oct 22, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code into the website's rendered copy running inside the end user's web browser. It does not allow injecting code into the real (isolated) copy of the website running on the WI Threat Isolation Engine.

VendorProductVersions

Symantec Corporation

Symantec Web Isolation

affected
1.11 prior to 1.11.21

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now