CVE-2012-1825
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a…
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the status program on the ForeScout CounterACT appliance with software 6.3.3.2 through 6.3.4.10 allow remote attackers to inject arbitrary web script or HTML via (1) the loginname parameter in a forgotpass action or (2) the username parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.99% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- forescout/counteract
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/815532US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8TWMEJUS Government Resource
- http://www.kb.cert.org/vuls/id/815532US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8TWMEJUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.