XSS Vulnerability in SZ NetChat before 7.9 Allows Command Injection

XSS Vulnerability in SZ NetChat before 7.9 Allows Command Injection

CVE-2018-20370 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.

Learn more about our Web App Pen Testing.