The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NGemalto Sentinel Ldk Rte
APPGemalto< 7.80
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2017-11496CRITICAL9.8PL ✓same product
Stack buffer overflow w Gemalto Sentinel LDK umożliwiający zdalne wykonanie kodu
CVE-2017-11497CRITICAL9.8PL ✓same product
Stack buffer overflow w Gemalto Sentinel LDK — RCE przez złośliwy pakiet językowy
CVE-2018-6304HIGH7.5same product
Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial o...
CVE-2018-6305HIGH7.5same product
Denial of service in Gemalto's Sentinel LDK RTE version before 7.65
CVE-2017-11498HIGH7.5same product
Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to S...