Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3r55-8c76-hvc2

Опубликовано: 17 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.

EPSS

Процентиль: 58%
0.00363
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

EPSS

Процентиль: 58%
0.00363
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79