Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6mvx-8cgw-xwh9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

EPSS

Процентиль: 59%
0.00385
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 14 лет назад

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

nvd
больше 14 лет назад

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

debian
больше 14 лет назад

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber ...

EPSS

Процентиль: 59%
0.00385
Низкий

Дефекты

CWE-79