vendor:
Kodi
by:
Manuel Garcia Cardenas
6.1
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Kodi
Affected Version From: Kodi <= 17.6
Affected Version To: Kodi <= 17.6
Patch Exists: YES
Related CWE: CVE-2018-8831
CPE: o:kodi:kodi
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Multiple
2018
Kodi <= 17.6 - Persistent Cross-Site Scripting
Has been detected a Persistent XSS vulnerability in the web interface of Kodi, that allows the execution of arbitrary HTML/script code to be executed in the context of the victim user's browser.
Mitigation:
Vendor include the fix: https://trac.kodi.tv/ticket/17814