Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-339f-fg4x-gwcm

Опубликовано: 10 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

EPSS

Процентиль: 56%
0.00344
Низкий

9 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9
nvd
около 2 лет назад

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

EPSS

Процентиль: 56%
0.00344
Низкий

9 Critical

CVSS3

Дефекты

CWE-79