Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4g5m-vrw9-vcj9

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

EPSS

Процентиль: 72%
0.00722
Низкий

Связанные уязвимости

nvd
около 22 лет назад

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

EPSS

Процентиль: 72%
0.00722
Низкий