Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxhj-2fv3-v798

Опубликовано: 03 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function will terminate the script and print the message to the user which has $_SERVER['HTTP_HOST'].

thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function will terminate the script and print the message to the user which has $_SERVER['HTTP_HOST'].

EPSS

Процентиль: 45%
0.00223
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].

EPSS

Процентиль: 45%
0.00223
Низкий

Дефекты

CWE-79