Cross-Site Scripting Vulnerability in m-server Module by an Unknown Vendor
CVE-2018-16484

5.4MEDIUM

Key Information:

Vendor

Hackerone

Status
Vendor
CVE Published:
1 February 2019

What is CVE-2018-16484?

A Cross-Site Scripting (XSS) vulnerability exists in the m-server module versions prior to 1.4.2. This vulnerability arises from the inadequate escaping of special characters in folder names, which allows attackers to inject and execute malicious Javascript code or HTML. Exploiting this vulnerability could lead to unauthorized access or manipulation of user data, posing significant security risks to affected systems.

Affected Version(s)

m-server <1.4.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.