Security Advisory

CVE-2019-12930

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-07-08 19:20:28
Last updated 2024-08-04 23:32:55
Assigner mitre
State PUBLISHED

Description

A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via the method parameter.