AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-7650

MEDIUM · CVSS 4.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-03-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-7650
Severity
MEDIUM
CVSS
4.8
EPSS
0.54%
Java

Original NVD Description

PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitize user supplied input to the name parameter, and renders injected JavaScript code to the user's browser. This is different from CVE-2018-6878.

Related CVEs

Other vulnerabilities affecting the same vendor(s)