Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8jj-6823-vfgv

Опубликовано: 30 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.

EPSS

Процентиль: 43%
0.00206
Низкий

Дефекты

CWE-79