CVE-2018-2388 describes a stored cross-site scripting (XSS) vulnerability affecting multiple versions of the SAP Internet Graphics Server (IGS), specifically 7.20, 7.20EXT, 7.45, 7.49, and 7.53. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed when a user views the compromised content. With a CVSS score of 6.1 (Medium), this vulnerability has a network-based attack vector requiring user interaction (UI:R) but low attack complexity (AC:L). A successful exploit could lead to limited confidentiality and integrity impacts (C:L, I:L), such as session hijacking or defacement, but no availability impact (A:N). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.20CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.20:*:*:*:*:*:*:* | ||
7.20extCPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.20ext:*:*:*:*:*:*:* | ||
7.45CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.45:*:*:*:*:*:*:* | ||
7.49CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.49:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.53:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.