Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85rm-jm8v-379f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

EPSS

Процентиль: 39%
0.00173
Низкий

7.5 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

EPSS

Процентиль: 39%
0.00173
Низкий

7.5 High

CVSS3

Дефекты

CWE-352