CVE-2018-15533
MEDIUMGeutebrueck re_porter 16 < 7.8.974.20 - Reflected Cross-Site Scripting via Query String
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-15533. PoCs published by Kamil Suska.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Geutebrueck re_porter versions prior to 7.8.974.20. The attack vectors inject JavaScript payloads into URL parameters, triggering arbitrary script execution in the context of the victim's browser.
Description
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Geutebrueck re_porter versions prior to 7.8.974.20. The attack vectors inject JavaScript payloads into URL parameters, triggering arbitrary script execution in the context of the victim's browser.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N