Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
References
Link | Resource |
---|---|
https://gist.github.com/priyanksethi/08fb93341cf7e61344aad5c4fee3aa9b | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-06-07 18:29
Updated : 2018-07-31 10:38
NVD link : CVE-2018-9182
Mitre link : CVE-2018-9182
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
lynxtechnology
- twonky_server