CVE Database
/

CVE-2018-15699

Back to search

CVE-2018-15699

Published: Aug 27, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.

VendorProductVersions

Tenable

ASUSTOR Data Master

affected
3.1.5 and below

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now