peter bassill · operator
$ cve CVE-2018-12234 JSON

CVE-2018-12234 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS2.95% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2018-09-06
Last modified2026-06-17

Affected (1)

VendorProduct
myadrenalinadrenalin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD