Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v94-m4qx-qvc5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.

EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.

EPSS

Процентиль: 42%
0.00197
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
nvd
больше 4 лет назад

EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.

EPSS

Процентиль: 42%
0.00197
Низкий

Дефекты

CWE-79