CVE-2018-16484: M-Server Project M-Server
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.
Affected products
- M-Server Project M-Server: before 1.4.2 (fixed in 1.4.2)
Published 2019-02-01. Last modified 2026-06-17.