CVE-2018-8600 is a Cross-site Scripting (XSS) vulnerability affecting Microsoft Azure App Services on Azure Stack, stemming from improper sanitization of user-provided input. This medium-severity vulnerability (CVSS 6.1) requires user interaction and can lead to low impact on confidentiality and integrity. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community discussion and media coverage. It is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_app_service_on_azure_stack:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.