VYPR
Unrated severityOSV Advisory· Published Jan 29, 2019· Updated Aug 5, 2024

CVE-2018-19782

CVE-2018-19782

Description

Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • FreshRSS/FreshrssOSV2 versions
    0.1.0, 0.5.0, 0.6.0, …+ 1 more
    • (no CPE)range: 0.1.0, 0.5.0, 0.6.0, …
    • (no CPE)range: <=1.11.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.