CVE-2018-1000528

Published: 26 June 2018

GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to have been fixed in after commit 56070d6289d47ba3f5918885954dcceb75606001.

Priority

Medium

CVSS 3 base score: 6.1

Status

Package Release Status
gosa
Launchpad, Ubuntu, Debian
Upstream
Released (2.7.4+reloaded3-5)
Ubuntu 20.10 (Groovy Gorilla) Not vulnerable
(2.7.4+reloaded3-5)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(2.7.4+reloaded3-5)
Ubuntu 18.04 LTS (Bionic Beaver) Needed

Ubuntu 16.04 LTS (Xenial Xerus)
Released (2.7.4+reloaded2-9ubuntu1.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needs-triage)
Ubuntu 12.04 ESM (Precise Pangolin) Does not exist