Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6889-wccr-m7x3

Опубликовано: 06 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.

Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.

EPSS

Процентиль: 47%
0.00238
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.

EPSS

Процентиль: 47%
0.00238
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79