Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-25w4-83pf-9vjv

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.

Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.

EPSS

Процентиль: 74%
0.00828
Низкий

Связанные уязвимости

nvd
почти 21 год назад

Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.

EPSS

Процентиль: 74%
0.00828
Низкий