Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97pv-4338-r5vp

Опубликовано: 07 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

Cross-site Scripting in file-upload-with-preview

This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).

Пакеты

Наименование

file-upload-with-preview

npm
Затронутые версииВерсия исправления

< 4.2.0

4.2.0

EPSS

Процентиль: 61%
0.00412
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.2
nvd
больше 4 лет назад

This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).

EPSS

Процентиль: 61%
0.00412
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-79