VYPR
Medium severity6.1OSV Advisory· Published Oct 24, 2018· Updated Jun 17, 2026

CVE-2018-18635

CVE-2018-18635

Description

www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows XSS via the admin/login/user/message/ PATH_INFO.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • (expand)+ 3 more
    • (no CPE)
    • cpe:2.3:a:mailcleaner:mailcleaner:2018.08:*:*:*:community:*:*:*
    • cpe:2.3:a:mailcleaner:mailcleaner:2018.09:*:*:*:community:*:*:*
    • (no CPE)range: 2018.08, 2018.09

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.