Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gpv-g6wh-j3p9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

EPSS

Процентиль: 54%
0.00318
Низкий

Дефекты

CWE-79

Связанные уязвимости

nvd
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

debian
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManag ...

EPSS

Процентиль: 54%
0.00318
Низкий

Дефекты

CWE-79