PoC Index

CVE-2016-8581

MEDIUM 6.1EPSS 17.1%

A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.

CVSS v3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
17.06% chance of exploitation in the next 30 days, 97th percentile
Published
2016-10-28
Updated
2024-08-06

Metasploit modules (1)

ExploitDB entries (1)

References

Related