{
    "id": "CVE-2018-12234",
    "published": "2018-09-06 23:29:00",
    "last_modified": "2026-06-17 01:37:24",
    "cvss_score": "6.1",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
    "cwe": "CWE-79",
    "description": "A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.",
    "epss_score": "0.02946",
    "epss_percentile": "0.86692",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-05 18:17:17",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "myadrenalin",
            "product": "adrenalin"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "47611",
            "title": "Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting",
            "date": "2019-11-12",
            "url": "https://www.exploit-db.com/exploits/47611"
        }
    ],
    "refs_list": [
        "http://packetstormsecurity.com/files/155231/Adrenalin-Core-HCM-5.4.0-Cross-Site-Scripting.html",
        "https://www.knowcybersec.com/2018/09/first-cve-2018-12234-reflected-XSS.html",
        "https://www.securethy.com/2018/09/first-cve-2018-12234-reflected-XSS.html",
        "https://www.thecysec.in/2020/04/xxs-adrenalin-generalinfo-cve-id.html",
        "http://packetstormsecurity.com/files/155231/Adrenalin-Core-HCM-5.4.0-Cross-Site-Scripting.html",
        "https://www.knowcybersec.com/2018/09/first-cve-2018-12234-reflected-XSS.html",
        "https://www.thecysec.in/2020/04/xxs-adrenalin-generalinfo-cve-id.html"
    ]
}