Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39cr-wrpx-ww2j

Опубликовано: 08 нояб. 2024
Источник: github
Github: Не прошло ревью

Описание

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.

EPSS

Процентиль: 54%
0.00316
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.

EPSS

Процентиль: 54%
0.00316
Низкий