Security Advisory
CVE-2018-9015
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).