Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-74ff-gjvr-p97p

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.

Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.

EPSS

Процентиль: 44%
0.00217
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.

CVSS3: 5.4
debian
около 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the file types ...

EPSS

Процентиль: 44%
0.00217
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79