Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wc9-7mc8-3qmr

Опубликовано: 16 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.

A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.

EPSS

Процентиль: 25%
0.00083
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
10 месяцев назад

A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.

EPSS

Процентиль: 25%
0.00083
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79