Cross-Site Scripting Vulnerability in m-server Module by an Unknown Vendor
CVE-2018-16484
5.4MEDIUM
What is CVE-2018-16484?
A Cross-Site Scripting (XSS) vulnerability exists in the m-server module versions prior to 1.4.2. This vulnerability arises from the inadequate escaping of special characters in folder names, which allows attackers to inject and execute malicious Javascript code or HTML. Exploiting this vulnerability could lead to unauthorized access or manipulation of user data, posing significant security risks to affected systems.
Affected Version(s)
m-server <1.4.2