Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-9282
HistorySep 21, 2018 - 4:29 p.m.

Cross site scripting

2018-09-2116:29:00
PRIOn knowledge base
www.prio-n.com
4

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.view; no administrator access is required. By injecting a JavaScript payload, this flaw could be used to manipulate a user’s session, or elevate privileges by targeting an administrative user.

CPENameOperatorVersion
subsoniceq6.1.1

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

Related for PRION:CVE-2018-9282