CVE-2018-12302: XSS
Published May 13, 2019
·Updated
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
Affected Software
1 affected component
Seagate NAS OS=4.3.15.1
Event History
May 13, 2019
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12302?
CVE-2018-12302 has a medium severity rating due to the risk of session token theft through cross-site scripting.
2
How do I fix CVE-2018-12302?
To fix CVE-2018-12302, configure session cookies to include the HTTPOnly flag in Seagate NAS OS version 4.3.15.1.
3
What systems are affected by CVE-2018-12302?
CVE-2018-12302 specifically affects Seagate NAS OS version 4.3.15.1.
4
What type of attack does CVE-2018-12302 enable?
CVE-2018-12302 enables attackers to perform cross-site scripting attacks to steal session tokens.
5
Is there a patch available for CVE-2018-12302?
As of now, there is no official patch released for CVE-2018-12302, but it is recommended to secure session cookies.