Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pqr-mwfx-8q8w

Опубликовано: 22 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

EPSS

Процентиль: 92%
0.089
Низкий

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 6 лет назад

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

CVSS3: 9.6
nvd
около 6 лет назад

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

CVSS3: 9.6
debian
около 6 лет назад

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 thr ...

EPSS

Процентиль: 92%
0.089
Низкий