Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52p8-m5r2-c245

Опубликовано: 04 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

EPSS

Процентиль: 25%
0.00088
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

EPSS

Процентиль: 25%
0.00088
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79