Unknown · Phodal Cmd · CVE-2020-18280
**Name of the Vulnerable Software and Affected Versions**
Phodal CMD version 1.0
**Description**
A Cross Site Scripting issue allows a local attacker to execute arbitrary code via the EMBED SRC function. This enables the attacker to perform unauthorized actions on the system.
**Recommendations**
For Phodal CMD version 1.0, consider disabling the EMBED SRC function as a temporary workaround until a patch is available. Restrict access to the function to minimize the risk of exploitation.