CVE-2018-19178

In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
References
Link Resource
https://github.com/zchuanzhao/jeesns/issues/6 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:jeesns:jeesns:1.3:*:*:*:*:*:*:*

Information

Published : 2018-11-11 04:29

Updated : 2018-12-13 04:03


NVD link : CVE-2018-19178

Mitre link : CVE-2018-19178

Products Affected
No products.
CWE