2024-12-08 03:06:42 +00:00

129 lines
3.9 KiB
JSON

{
"id": "CVE-2018-18362",
"sourceIdentifier": "secure@symantec.com",
"published": "2018-12-06T19:29:00.230",
"lastModified": "2024-11-21T03:55:47.603",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy."
},
{
"lang": "es",
"value": "Norton Password Manager para Android (anteriormente Norton Identity Safe) podr\u00eda ser susceptible a un exploit Cross-Site Scripting (XSS), que es un tipo de problema que puede permitir que los atacantes inyecten scripts del lado del cliente en p\u00e1ginas web visualizadas por otros usuarios. Podr\u00eda emplearse una vulnerabilidad Cross-Site Scripting (XSS) para omitir los controles de acceso como la pol\u00edtica same-origin."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:symantec:norton_password_manager:*:*:*:*:*:android:*:*",
"versionEndExcluding": "6.1.0.1045",
"matchCriteriaId": "C11AE531-A018-4F21-B899-8B8C6E52E916"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/106055",
"source": "secure@symantec.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://support.symantec.com/en_US/article.SYMSA1470.html",
"source": "secure@symantec.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/106055",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://support.symantec.com/en_US/article.SYMSA1470.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}