CVE-2018-8832
Dashboard / Vulnerabilities / CVE-2018-8832
CVE-2018-8832
Published: 20 Mar 2018Last Modified: 8 Jul 2026
Summary:
Details: enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack launches when a victim visits the admin user group page.
References: https://github.com/enhavo/enhavo/issues/459
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- b2647f4d070b3c26cbb7d235707f23a9c69b0117
Fixed -None
Affected versions
0.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
