CVE-2018-19782: XSS
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19782?
CVE-2018-19782 is a vulnerability in FreshRSS 1.11.1 that allows remote attackers to inject arbitrary web script or HTML via the c or a parameter in GET requests.
What is the severity of CVE-2018-19782?
CVE-2018-19782 has a severity rating of medium.
How can remote attackers exploit CVE-2018-19782?
Remote attackers can exploit CVE-2018-19782 by injecting arbitrary web script or HTML via the c or a parameter in GET requests.
What is the affected version of FreshRSS?
FreshRSS version 1.11.1 is affected by CVE-2018-19782.
Are there any known solutions for CVE-2018-19782?
At this time, there are no known solutions available for CVE-2018-19782. It is recommended to apply any patches or updates provided by the vendor when they become available.