Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5369-cwvv-7r63

Опубликовано: 04 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.5

Описание

A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

EPSS

Процентиль: 1%
0.00011
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.5
nvd
3 дня назад

A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

CVSS3: 6.5
debian
3 дня назад

A non-administrative user can upload malicious files. When an administ ...

EPSS

Процентиль: 1%
0.00011
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-434