ZeroHour

CVE-2018-20729

PoC
CVSS 3.0
6.1 medium
EPSS
<1%p55
Published
()
Modified
Description

A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via the reg parameter in mh.php.

Vendors
nedi
Products
nedi
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.