CVE-2018-11450

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/07/2018
Last modified:
09/10/2019

Description

A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3 and newer are not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:teamcenter_product_lifecycle_management:*:*:*:*:*:*:*:* 9.1.2.5 (including)