CVE-2018-1000642

FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
flightairmapflightairmap
0.1:beta1
flightairmapflightairmap
0.2:beta1
flightairmapflightairmap
0.5:beta1
flightairmapflightairmap
0.6:beta1
flightairmapflightairmap
1.0:beta1
flightairmapflightairmap
1.0:beta10
flightairmapflightairmap
1.0:beta11
flightairmapflightairmap
1.0:beta12
flightairmapflightairmap
1.0:beta13
flightairmapflightairmap
1.0:beta14
flightairmapflightairmap
1.0:beta15
flightairmapflightairmap
1.0:beta16
flightairmapflightairmap
1.0:beta17
flightairmapflightairmap
1.0:beta18
flightairmapflightairmap
1.0:beta19
flightairmapflightairmap
1.0:beta2
flightairmapflightairmap
1.0:beta20
flightairmapflightairmap
1.0:beta21
flightairmapflightairmap
1.0:beta3
flightairmapflightairmap
1.0:beta4
flightairmapflightairmap
1.0:beta5
flightairmapflightairmap
1.0:beta6
flightairmapflightairmap
1.0:beta7
flightairmapflightairmap
1.0:beta8
flightairmapflightairmap
1.0:beta9
𝑥
= Vulnerable software versions