CVE-2018-16481
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Affected products
HackerOne · html-pagesReferences
https://hackerone.com/reports/330356