CVE-2018-6014
Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a web site loaded with a SWF file created specifically to steal user data.
- Affected products
- Subsonic
- Subsonic
- = 6.1.3
- Fix
- Available
- CVSS 3.0
- 6.5 MEDIUM
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2018-01-23
CVE-2018-6014 at NVD
2 known exploits for CVE-2018-6014
Proof-of-concept code and exploit modules indexed by Sploitus