Critical XSS Vulnerability in m-server <1.4.2: Execution of Malicious Code via Unescaped Folder Names

Critical XSS Vulnerability in m-server <1.4.2: Execution of Malicious Code via Unescaped Folder Names

CVE-2018-16484 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.

Learn more about our Cis Benchmark Audit For Server Software.