Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf2f-3xch-87w9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "core/admin/adjax/dashboard/check-module-integrity.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "core/admin/adjax/dashboard/check-module-integrity.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

EPSS

Процентиль: 33%
0.00129
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.4
nvd
почти 9 лет назад

An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "core/admin/adjax/dashboard/check-module-integrity.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

EPSS

Процентиль: 33%
0.00129
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-284