{"api_version":"1","generated_at":"2026-07-23T09:34:00+00:00","cve":"CVE-2018-14875","urls":{"html":"https://cve.report/CVE-2018-14875","api":"https://cve.report/api/cve/CVE-2018-14875.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-14875","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-14875"},"summary":{"title":"CVE-2018-14875","description":"An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-04-30 19:29:00","updated_at":"2019-05-03 15:19:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://neetech18.blogspot.com/2019/03/reflected-xss-vulnerability-in-polaris.html","name":"https://neetech18.blogspot.com/2019/03/reflected-xss-vulnerability-in-polaris.html","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Reflected XSS Vulnerability in Polaris’ Intellect Core Banking Software Version 9.7.1 [CVE-2018-14875]","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-14875","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14875","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"14875","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"polarisft","cpe5":"intellect_core_banking","cpe6":"9.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14875","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"polarisft","cpe5":"intellect_core_banking","cpe6":"9.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-14875","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://neetech18.blogspot.com/2019/03/reflected-xss-vulnerability-in-polaris.html","url":"https://neetech18.blogspot.com/2019/03/reflected-xss-vulnerability-in-polaris.html"}]}},"nvd":{"publishedDate":"2019-04-30 19:29:00","lastModifiedDate":"2019-05-03 15:19:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:polarisft:intellect_core_banking:9.7.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"14875","Ordinal":"131609","Title":"CVE-2018-14875","CVE":"CVE-2018-14875","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"14875","Ordinal":"1","NoteData":"An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"14875","Ordinal":"2","NoteData":"2019-04-30","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"14875","Ordinal":"3","NoteData":"2019-04-30","Type":"Other","Title":"Modified"}]}}}