CVE-2018-7894: Eramba
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter).
Affected products
- Eramba Eramba: version e1.0.6.033 only
Published 2018-03-09. Last modified 2026-06-17.