VYPR
High severity8.8OSV Advisory· Published Mar 7, 2018· Updated Jun 17, 2026

CVE-2018-7746

CVE-2018-7746

Description

An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example, with a crafted channel name, stored XSS is triggered during a later /index.php?/manage/channel request by an admin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Cobub/RazorOSV2 versions
    v0.1, v0.3.1, v0.4, …+ 1 more
    • (no CPE)range: v0.1, v0.3.1, v0.4, …
    • cpe:2.3:a:cobub:razor:0.7.2:*:*:*:*:*:*:*
  • Range: =0.7.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.