Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v3w-m552-m6ff

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Pi Cross-site Scripting vulnerability

A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the pi-develop/www/script/editor/markitup/preview/markdown.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

Пакеты

Наименование

pi/pi

composer
Затронутые версииВерсия исправления

<= 2.5.0

2.6.0-alpha1

EPSS

Процентиль: 46%
0.00234
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 9 лет назад

A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the "pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

EPSS

Процентиль: 46%
0.00234
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79