Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j5r-4fc9-3v6r

Опубликовано: 09 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.9
CVSS3: 2.4

Описание

A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

EPSS

Процентиль: 7%
0.00026
Низкий

1.9 Low

CVSS4

2.4 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 2.4
nvd
около 1 месяца назад

A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

EPSS

Процентиль: 7%
0.00026
Низкий

1.9 Low

CVSS4

2.4 Low

CVSS3

Дефекты

CWE-79