Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hf94-8mx5-2vvj

Опубликовано: 21 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-site Scripting in kiwitcms

A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.

Пакеты

Наименование

kiwitcms

pip
Затронутые версииВерсия исправления

< 11.6

11.6

EPSS

Процентиль: 55%
0.00327
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.

EPSS

Процентиль: 55%
0.00327
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79