NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.Referenceshttps://www.nedi.ch/download/https://gist.github.com/sudoninja-noob/c1722c118abc7a562a9a0de726266a19