Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43m5-x878-2c62

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

EPSS

Процентиль: 55%
0.00327
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 5 лет назад

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

EPSS

Процентиль: 55%
0.00327
Низкий

Дефекты

CWE-79