NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15037
Reference (s):
- https://gist.github.com/sudoninja-noob/c1722c118abc7a562a9a0de726266a19
- https://www.nedi.ch/download/

