Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98qf-xpr5-r2xv

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 8.8

Описание

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.

EPSS

Процентиль: 9%
0.00032
Низкий

5.1 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 месяцев назад

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.

EPSS

Процентиль: 9%
0.00032
Низкий

5.1 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-79