CVE-2018-7894: Eramba

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter).

Affected products

  • Eramba Eramba: version e1.0.6.033 only

Published 2018-03-09. Last modified 2026-06-17.