Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfm8-2q22-h7hv

Опубликовано: 15 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-site Scripting in pegasus/google-for-jobs

An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.

Пакеты

Наименование

pegasus/google-for-jobs

composer
Затронутые версииВерсия исправления

< 1.5.1

1.5.1

Наименование

pegasus/google-for-jobs

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.1

2.1.1

EPSS

Процентиль: 43%
0.00206
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.

EPSS

Процентиль: 43%
0.00206
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79