Security Advisory
CVE-2018-8831
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim users browser via a playlist.