Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43f8-j7wq-qhwm

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

EPSS

Процентиль: 54%
0.0031
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

CVSS3: 6.1
nvd
около 8 лет назад

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

CVSS3: 6.1
debian
около 8 лет назад

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0 ...

EPSS

Процентиль: 54%
0.0031
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79