Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r3m-j6x5-48m3

Опубликовано: 28 авг. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

Пакеты

Наименование

baserproject/basercms

composer
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.3.6

4.3.7

EPSS

Процентиль: 75%
0.00868
Низкий

7.3 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.3
nvd
больше 5 лет назад

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

EPSS

Процентиль: 75%
0.00868
Низкий

7.3 High

CVSS3

Дефекты

CWE-79