CVE-2018-20472

MEDIUM

Sahipro Sahi Pro < 8.0.0 - XSS

Title source: rule
STIX 2.1

Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.

Exploits (1)

exploitdb WORKING POC
by Goutham Madhwaraj · textwebappsmultiple
https://www.exploit-db.com/exploits/47007

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
sahipro/sahi_pro < 8.0.0
Published Jun 17, 2019
Tracked Since Feb 18, 2026