CVE-2018-19782
MEDIUMFreshRSS 1.11.1 - Cross-Site Scripting via GET Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19782. PoCs published by Netsparker.
AI-analyzed exploit summary The document describes multiple XSS vulnerabilities in FreshRSS 1.11.1, including blind, stored, and reflected XSS. It provides URLs, parameters, and attack patterns but does not include executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.
Exploits (1)
The document describes multiple XSS vulnerabilities in FreshRSS 1.11.1, including blind, stored, and reflected XSS. It provides URLs, parameters, and attack patterns but does not include executable exploit code.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N