Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pg4-q67x-c7x9

Опубликовано: 30 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79