Medium severity6.1NVD Advisory· Published Jun 29, 2020· Updated Jun 17, 2026
CVE-2020-14413
CVE-2020-14413
Description
NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- gist.github.com/farid007/8db2ab5367ba00e87f9479b32d46fea8nvdThird Party Advisory
News mentions
0No linked articles in our index yet.