RULE(RULE ID:321842)

Rule General Information
Release Date: 2019-06-14
Rule Name: Advantech WebAccess Cross-site Scripting Vulnerability (CVE-2018-15707)
Severity:
CVE ID:
Rule Protection Details
Description: Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: ExploitDB:45774
https://www.tenable.com/security/research/tra-2018-35
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.advantech.com.cn/