← back
CVE-2018-8006

CVE-2018-8006

EPSS 56.2%
Vexday Risk Score
30Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 56.2%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
10 Oct 2018Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →