Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fxf-xgrm-8fcj

Опубликовано: 28 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.

Пакеты

Наименование

FormCMS

nuget
Затронутые версииВерсия исправления

< 0.5.7

0.5.7

EPSS

Процентиль: 20%
0.00063
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-434
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
5 месяцев назад

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.

EPSS

Процентиль: 20%
0.00063
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-434
CWE-79