paintballrefjosh/MaNGOSWebV4 < 4.0.8 contains a reflected XSS caused by unsanitized input in install/index.php (step parameter), letting attackers execute arbitrary scripts in the victim's browser, exploit requires victim to visit a maliciously crafted URL
id: CVE-2017-6478
info:
name: MaNGOSWebV4 < 4.0.8 - Cross-Site Scripting
author: 0xr2r
severi
...