Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89rc-4jgm-q84x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.

Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.

EPSS

Процентиль: 36%
0.00148
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.

EPSS

Процентиль: 36%
0.00148
Низкий

Дефекты

CWE-79