Description Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI. Remediation References CVE-2018-12100 Related Vulnerabilities WordPress Plugin Nextend Google Connect Unspecified Vulnerability (1.5.3) MyBB Other Vulnerability (CVE-2007-2212) MySQL CVE-2019-2534 Vulnerability (CVE-2019-2534) Claroline Other Vulnerability (CVE-2006-1594) WordPress 3.7.x Arbitrary File Deletion Vulnerability (3.7 - 3.7.26) Severity Medium Classification CVE-2018-12100 CWE-707 CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities