CVE-2018-16484
MEDIUMM-server < 1.4.2 - XSS
Title source: ruleDescription
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0016
EPSS Percentile
36.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
m-server_project/m-server
< 1.4.2
npm/m-server
0 - 1.4.2npm
Published
Feb 01, 2019
Tracked Since
Feb 18, 2026