Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x4m-7295-wr3j

Опубликовано: 19 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

EPSS

Процентиль: 75%
0.00878
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 лет назад

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

CVSS3: 6.1
nvd
около 2 лет назад

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

CVSS3: 6.1
debian
около 2 лет назад

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of a ...

EPSS

Процентиль: 75%
0.00878
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79