← Vulnerability feed

Vulnerability record · CVE-2018-12302 · published 13 May 2019

CVE-2018-12302: Seagate nas os cross-site scripting vulnerability

Seagate · Nas Os

Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

6.1 CVSS 3.0 Medium EPSS 0.80% · top 45.1% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12302 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12295Seagate nas os sql injection vulnerabilitySQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL param…EPSS 1.1%7.5CVE-2018-12296Seagate nas os incorrect permission assignment vulnerabilityInsufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information ab…EPSS 11%7.5CVE-2018-12298Seagate nas os path traversal vulnerabilityDirectory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.EPSS 1.7%7.5CVE-2018-12301Seagate nas os information exposure vulnerabilityUnvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.…EPSS 1.4%6.1CVE-2018-12297Seagate nas os cross-site scripting vulnerabilityCross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.EPSS 0.69%6.1CVE-2018-12300Seagate nas os open redirect vulnerabilityArbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'sta…EPSS 3.1%6.1CVE-2018-12304Seagate nas os cross-site scripting vulnerabilityCross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metada…EPSS 0.83%5.4CVE-2018-12299Seagate nas os cross-site scripting vulnerabilityCross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2018-12302), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.