Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qpx-rx7g-pcgc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.

EPSS

Процентиль: 55%
0.00329
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
nvd
больше 4 лет назад

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.

EPSS

Процентиль: 55%
0.00329
Низкий

Дефекты

CWE-79