Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6jp-c7w6-m434

Опубликовано: 21 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.

The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.

EPSS

Процентиль: 33%
0.00134
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
почти 3 года назад

The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.

CVSS3: 5.3
debian
почти 3 года назад

The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sa ...

EPSS

Процентиль: 33%
0.00134
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22