Security Advisory
CVE-2018-18308
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).