Nexus Repository Manager Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-12100 - Vulnerability Database

Nexus Repository Manager Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-12100

Medium
Reference: CVE-2018-12100
Title: Nexus Repository Manager Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.