ZeroHour

CVE-2018-16096

CVSS 3.0
6.1 medium
EPSS
<1%p49
Published
()
Modified
Description

In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.

Vendors
lenovo
Products
system management module firmware
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.