Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxw9-g6g5-mfqx

Опубликовано: 22 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

EPSS

Процентиль: 90%
0.05524
Низкий

8.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.2
nvd
11 месяцев назад

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

EPSS

Процентиль: 90%
0.05524
Низкий

8.2 High

CVSS3

Дефекты

CWE-79