CVE-2018-8978: Open-Audit
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
Affected products
- Open-Audit Open-Audit: version 2.1 only
Published 2018-03-25. Last modified 2026-06-17.