CVE-2018-13065: Owasp Modsecurity
Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured
Affected products
- Owasp Modsecurity: version 3.0.0 only
Published 2018-07-03. Last modified 2026-06-17.