CVE-2018-11628
01.06.2018, 15:29
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.
| Vendor | Product | Version |
|---|---|---|
| emssoftware | ems_master_calendar | 𝑥 < 8.0.0.201805210 |
𝑥
= Vulnerable software versions
References