The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.
References
Configurations
Information
Published : 2018-05-02 14:29
Updated : 2018-06-13 18:29
NVD link : CVE-2018-8900
Mitre link : CVE-2018-8900
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
gemalto
- sentinel_ldk_rte