PT-2026-24148 · Fmdns+1 · Fmdns+1

Rusi-Sec

·

Publicado

2026-03-09

·

Atualizado

2026-03-13

·

CVE-2026-30918

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions facileManager versions prior to 6.0.4
Description facileManager is a modular suite of web apps designed for system administrators. A reflected cross-site scripting (XSS) issue exists when the application processes data from an untrusted source and incorporates it into HTTP responses, potentially leading to security compromises. An attacker can inject malicious JavaScript code into a URL by including a script within a parameter. This vulnerability is present in the fmDNS module, specifically affecting the log search query parameter.
Recommendations Update to version 6.0.4 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30918
GHSA-284F-MFF7-744X

Produtos afetados

File Manager
Fmdns