Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gx4g-83m8-7hhx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

EPSS

Процентиль: 51%
0.00275
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
около 5 лет назад

Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

EPSS

Процентиль: 51%
0.00275
Низкий

Дефекты

CWE-79