Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm7f-hf2g-ghrp

Опубликовано: 25 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9

Описание

PyroCMS vulnerable to stored Cross Site Scripting

PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS) when a low privileged user, such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

Пакеты

Наименование

pyrocms/pyrocms

composer
Затронутые версииВерсия исправления

<= 3.9.1

Отсутствует

EPSS

Процентиль: 61%
0.0041
Низкий

9 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9
nvd
около 3 лет назад

PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

EPSS

Процентиль: 61%
0.0041
Низкий

9 Critical

CVSS3

Дефекты

CWE-79