Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmgq-fmcq-h3xj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

EPSS

Процентиль: 39%
0.00176
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

EPSS

Процентиль: 39%
0.00176
Низкий

Дефекты

CWE-79