← back
CVE-2018-8006observed exploitation

CVE-2018-8006

52Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 57%
from disclosure to weapon
Published on NVDOct 10
VulnCheck+1882d
exploitation probability
57%top 1% of all CVEs
observed exploitation
yesVulnCheck
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.