Описание
Cross-site scripting in ICEcoder
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
Пакеты
Наименование
icecoder/icecoder
composer
Затронутые версииВерсия исправления
<= 8.0
8.1
Связанные уязвимости
CVSS3: 5.4
nvd
больше 4 лет назад
In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
CVSS3: 5.4
fstec
больше 4 лет назад
Уязвимость компонента multipe-results.php редактора кода в браузере ICEcoder,