Back to Database
Status published
Medium
CVE-2018-12303
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1...
Vulnerability Description
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-12303
Credits & Attribution
No credits recorded in the NVD database.
More from seagate
View All →CVE-2021-43429
A Denial of Service vulnerability exists in CORTX-S3 Server as...
High
7.5
CVE-2020-6627
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and...
Unknown
0
CVE-2018-5347
Seagate Media Server in Seagate Personal Cloud has unauthenticated command...
Critical
9.8
CVE-2018-12304
Cross-site scripting in Application Manager in Seagate NAS OS version...
Medium
6.1
CVE-2018-12302
Missing HTTPOnly flag on session cookies in the Seagate NAS...
Medium
6.1
Affected Vendor
seagate
View all reports →Affected Software
nas os
Vulnerable Versions:
4.3.15.1
Timeline
Official Publish:
May 13th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.