Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-53620

Опубликовано: 26 нояб. 2024
Источник: debian
EPSS Низкий

Описание

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

Примечания

  • Non issue reported for spip, was also filed as #1088801

  • Disputed by upstream: The code is not executed inside the back-office, but only

  • on the public part, so only after being accepted by an admin. The script is

  • displayed in its raw form inside the back office, so an admin can see it and

  • decide to publish it or not.

EPSS

Процентиль: 24%
0.00082
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 1 года назад

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

CVSS3: 4.8
nvd
около 1 года назад

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

CVSS3: 4.8
github
около 1 года назад

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

EPSS

Процентиль: 24%
0.00082
Низкий