CVE-2018-12302: Seagate NAS OS

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

Affected products

  • Seagate NAS OS: version 4.3.15.1 only

Published 2019-05-13. Last modified 2026-06-17.