CVE-2018-13065: Owasp Modsecurity

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured

Affected products

  • Owasp Modsecurity: version 3.0.0 only

Published 2018-07-03. Last modified 2026-06-17.