Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-14413

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.157
EPSS Ranking 94.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-14413
  • Nedi » Nedi » Version: 1.9c
    cpe:2.3:a:nedi:nedi:1.9c


Contact Us

Shodan ® - All rights reserved