Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xvq-93jj-7c4r

Опубликовано: 02 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

EPSS

Процентиль: 16%
0.00052
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
4 месяца назад

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

EPSS

Процентиль: 16%
0.00052
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79