Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqqp-x5qv-896x

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 7.2

Описание

Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.

Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.

EPSS

Процентиль: 8%
0.00031
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
23 дня назад

Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.

EPSS

Процентиль: 8%
0.00031
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79