Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ff6v-2cx8-mf3h

Опубликовано: 29 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

SolidInvoice 2.3.7 and fixed in v.2.3.8 is vulnerable to Cross Site Scripting (XSS) in the Tax Rate functionality.

SolidInvoice 2.3.7 and fixed in v.2.3.8 is vulnerable to Cross Site Scripting (XSS) in the Tax Rate functionality.

EPSS

Процентиль: 17%
0.00052
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
5 месяцев назад

SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

EPSS

Процентиль: 17%
0.00052
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79