peter bassill · operator
$ cve CVE-2018-10763 JSON

CVE-2018-10763 EXPLOIT

4.8
MEDIUM · CVSS 3.0 · EPSS 1.7% (pctl 76)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page.

Scoring

CVSS4.8 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS1.65% — more likely to be exploited than 76% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2018-09-14
Last modified2026-06-17

Affected (1)

VendorProduct
synametricssynaman

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD