CVE-2018-3238 is a cross-site scripting (XSS) vulnerability in the Advanced UI subcomponent of Oracle WebCenter Sites 11.1.1.8.0, part of Oracle Fusion Middleware. This medium-severity vulnerability (CVSS 6.9) allows a highly privileged attacker with network access to compromise the system, requiring user interaction to succeed. Successful exploitation can lead to unauthorized access to critical data, complete data access, and unauthorized data modification within Oracle WebCenter Sites, potentially impacting additional products. While no active exploitation or public exploit code (Metasploit, ExploitDB) is confirmed, Nuclei templates exist for detecting the XSS, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:webcenter_sites:11.1.1.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.