Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g9ph-r9hc-34r8

Опубликовано: 21 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Erxes vulnerable to Cross-site Scripting

Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in all versions. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.

Пакеты

Наименование

erxes

npm
Затронутые версииВерсия исправления

<= 1.0.1

Отсутствует

EPSS

Процентиль: 99%
0.85495
Высокий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.22.3 and prior. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.

EPSS

Процентиль: 99%
0.85495
Высокий

6.1 Medium

CVSS3

Дефекты

CWE-79