Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvcw-x64m-pfcj

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4

Описание

Wallabag cross-site scripting (XSS) vulnerability

The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.

Пакеты

Наименование

wallabag/wallabag

composer
Затронутые версииВерсия исправления

>= 2.2.3, < 2.3.3

2.3.3

EPSS

Процентиль: 63%
0.00453
Низкий

4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4
nvd
больше 7 лет назад

The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.

EPSS

Процентиль: 63%
0.00453
Низкий

4 Medium

CVSS3

Дефекты

CWE-79