← All CVEs

CVE-2016-8581

medium · 6.1

A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.

6.1
CVSS
17.1%
EPSS (exploit prob.)
97th
EPSS percentile
2016-10-28
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
alienvaultopen_source_security_information_and_event_management<= 5.3.1
alienvaultunified_security_management<= 5.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-8581