CVE-2018-12302: Seagate NAS OS
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
Affected products
- Seagate NAS OS: version 4.3.15.1 only
Published 2019-05-13. Last modified 2026-06-17.