Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-564r-594w-gw2m

Опубликовано: 27 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

EPSS

Процентиль: 29%
0.00104
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

CVSS3: 5.4
nvd
около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

CVSS3: 5.4
debian
около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. ...

EPSS

Процентиль: 29%
0.00104
Низкий

Дефекты

CWE-79