CVE-2018-8832: Enhavo

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack launches when a victim visits the admin user group page.

Affected products

  • Enhavo Enhavo: version 0.4.0 only

Published 2018-03-20. Last modified 2026-06-17.