CVE-2018-25080 is a Cross-Site Scripting (XSS) vulnerability found in MobileDetect version 2.8.31, specifically within the initLayoutType function of the examples/session_example.php file. This vulnerability, rated Medium severity (CVSS 6.1), allows remote attackers to inject malicious scripts by manipulating the $_SERVER['PHP_SELF'] argument, potentially leading to information disclosure and defacement. While not actively exploited in the wild, an ExploitDB entry (EDB-52454) exists, and a patch is available by upgrading to version 2.8.32. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.31CPE matchmatch criteria | cpe:2.3:a:mobiledetect:mobiledetect:2.8.31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.