Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85hj-g8gj-8mxh

Опубликовано: 04 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.

Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.

EPSS

Процентиль: 32%
0.00124
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.

EPSS

Процентиль: 32%
0.00124
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79