Cross-Site Scripting Vulnerabilities in FreshRSS by FreshRSS
CVE-2018-19782
6.1MEDIUM
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2018-19782?
Multiple cross-site scripting (XSS) vulnerabilities exist in FreshRSS version 1.11.1, allowing remote attackers to inject arbitrary web scripts or HTML. These vulnerabilities affect GET requests that utilize the parameters (1) c and (2) a, potentially leading to unauthorized access and web application compromise. Mitigating these risks is crucial for maintaining a secure environment.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
