Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.00223 Percentile:
0.45067
CVSS Scoring
CVSS v3.0 Score: 6.1
Severity: MEDIUM
Mapped CWE(s)
CWE-79
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')