Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r68-qm7v-72rg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

EPSS

Процентиль: 83%
0.01831
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

EPSS

Процентиль: 83%
0.01831
Низкий