Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fm4-9v93-v7gg

Опубликовано: 13 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

EPSS

Процентиль: 75%
0.0087
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 3 лет назад

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

CVSS3: 6.1
nvd
около 3 лет назад

An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

CVSS3: 6.1
debian
около 3 лет назад

An issue was discovered in Nim before 1.6.2. The RST module of the Nim ...

EPSS

Процентиль: 75%
0.0087
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79