CVE-2026-30918
Status: AnalyzedMedium (6.1)—
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to inject malicious JavaScript code into a URL by adding a script in a parameter. This vulnerability was found in the fmDNS module. The parameter that is vulnerable to an XSS attack is log_search_query. This vulnerability is fixed in 6.0.4.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Base score: 6.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.29%
- Percentile among all scored CVEs: 19
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-30918",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-30918",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-03-10T14:20:05.587520Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "facileManager",
"product": "facileManager",
"versions": [
{
"status": "affected",
"version": "< 6.0.4"
}
]
}
]
}
],
"published": "2026-03-10T17:40:15.667",
"references": [
{
"url": "https://github.com/facileManager/facileManager/security/advisories/GHSA-284f-mff7-744x",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to inject malicious JavaScript code into a URL by adding a script in a parameter. This vulnerability was found in the fmDNS module. The parameter that is vulnerable to an XSS attack is log_search_query. This vulnerability is fixed in 6.0.4."
},
{
"lang": "es",
"value": "facileManager es una suite modular de aplicaciones web diseñada pensando en el administrador de sistemas. Antes de la versión 6.0.4, se produce un XSS reflejado cuando una aplicación recibe datos de una fuente no confiable y los utiliza en sus respuestas HTTP de una manera que podría generar vulnerabilidades. Es posible inyectar código JavaScript malicioso en una URL añadiendo un script en un parámetro. Esta vulnerabilidad fue encontrada en el módulo fmDNS. El parámetro que es vulnerable a un ataque XSS es log_search_query. Esta vulnerabilidad está corregida en la versión 6.0.4."
}
],
"lastModified": "2026-06-17T10:33:08.870",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:facilemanager:facilemanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACF32B72-7187-4B8C-B452-67ACBA089B76",
"versionEndExcluding": "6.0.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}