Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q6h-q44p-xw88

Опубликовано: 11 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

EPSS

Процентиль: 21%
0.00065
Низкий

7.3 High

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS3: 7.3
redhat
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS3: 7.3
nvd
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS3: 7.3
debian
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inser ...

CVSS3: 7.3
fstec
около 2 лет назад

Уязвимость языка программирования Go, связанная с ошибками при обработке специальных символов &quot;&lt;&gt;&quot; в контексте CSS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 21%
0.00065
Низкий

7.3 High

CVSS3

Дефекты

CWE-74
CWE-94