Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjvj-rr24-chm8

Опубликовано: 15 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.

Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.

EPSS

Процентиль: 25%
0.00086
Низкий

7.1 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.1
nvd
больше 2 лет назад

Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.

EPSS

Процентиль: 25%
0.00086
Низкий

7.1 High

CVSS3

Дефекты

CWE-434