Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3g6f-gvxf-2qx6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.

EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.

EPSS

Процентиль: 30%
0.00113
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.

EPSS

Процентиль: 30%
0.00113
Низкий