Back to search
CVE-2018-15312
Published: Oct 19, 2018
Modified: Sep 17, 2024
PUBLISHED
Description
On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.
| Vendor | Product | Versions |
|---|---|---|
F5 Networks, Inc. | BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) | affected 13.0.0-13.1.1.1affected 12.1.0-12.1.3.6 |
References
1041932
vdb-entry
x_refsource_SECTRACK
https://support.f5.com/csp/article/K44462254
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now