Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qfg-r6jr-q49h

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

EPSS

Процентиль: 47%
0.00243
Низкий

Связанные уязвимости

nvd
больше 11 лет назад

Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

debian
больше 11 лет назад

Incomplete blacklist vulnerability in the autoEscape function in commo ...

EPSS

Процентиль: 47%
0.00243
Низкий