NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/p4nk4jv/NeDi-1.9C-Multiple-CVEs