LiveActive security incident?Get immediate response
CVE Record

CVE-2018-7996: Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.

Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2018-7996 is a stored cross-site scripting issue reported in Eramba e1.0.6.033. Malicious content saved in a program scope description could later run in another user's browser when shown in a tooltip. The source bundle does not provide CVSS, confirmed fixed versions, or evidence of active exploitation.

Executive priority

Handle as a targeted application security fix for any Eramba e1.0.6.033 deployment. It is not supported as an emergency internet-wide issue by the provided sources, but stored XSS can affect user trust, session security, and governance data integrity.

Technical view

The CVE states Eramba e1.0.6.033 has stored XSS in the tooltip box through the /programScopes description parameter. The available data does not define affected CPEs, privileges required, impact scope, or vendor remediation. Treat validation as version and route exposure confirmation plus review of stored description content.

Likely exposure

Exposure appears limited to organizations running Eramba e1.0.6.033, especially where users can create or edit program scope descriptions and other users view them. The bundle does not establish exposure for other Eramba versions or products.

Exploitation context

The CVE is not listed as KEV in the provided bundle, and no cited source states active exploitation. The public reference indicates a reported security issue, but the bundle lacks exploit status, attack prevalence, or remediation confirmation.

Researcher notes

Evidence is sparse: the CVE record names the route and parameter but omits CVSS, CWE, CPEs, privileges, and fixes. Do not generalize beyond Eramba e1.0.6.033 unless additional vendor or maintainer evidence confirms other versions.

Mitigation direction

  • Check Eramba vendor or project guidance for fixed versions or official remediation.
  • Limit access to program scope creation and editing to trusted users.
  • Review stored program scope descriptions for suspicious markup or script-like content.
  • Apply output encoding or sanitization if maintaining a fork or custom deployment.
  • Prioritize upgrade or compensating controls for internet-accessible Eramba instances.

Validation and detection

  • Inventory Eramba deployments and confirm whether version e1.0.6.033 is present.
  • Confirm whether /programScopes is enabled and reachable by authenticated users.
  • Review roles allowed to create or edit program scope descriptions.
  • Inspect existing program scope descriptions for unexpected HTML or JavaScript indicators.
  • Verify vendor documentation before claiming a patched state.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-7996 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.