Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hpg-33j4-xvq2

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Resume parameter. The XSS is loaded from /register.ghp.

Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Resume parameter. The XSS is loaded from /register.ghp.

EPSS

Процентиль: 35%
0.00146
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Resume parameter. The XSS is loaded from /register.ghp.

EPSS

Процентиль: 35%
0.00146
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79