Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf64-8857-h96q

Опубликовано: 02 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.

EPSS

Процентиль: 13%
0.00044
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
2 месяца назад

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.

CVSS3: 6.1
nvd
2 месяца назад

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.

CVSS3: 6.1
debian
2 месяца назад

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v ...

EPSS

Процентиль: 13%
0.00044
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79