Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc63-hf4q-596r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.

Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.

EPSS

Процентиль: 53%
0.00307
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed during a convert transaction action.

EPSS

Процентиль: 53%
0.00307
Низкий

Дефекты

CWE-79