CVE-2018-16096
—CVSS 3.0
6.1 medium
EPSS
<1%p49
Published
()
Modified
Description
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
- Vendors
- lenovo
- Products
- system management module firmware
- Weakness
- CWE-79
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.