Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jghx-rx2p-62q9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

EPSS

Процентиль: 94%
0.13254
Средний

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

EPSS

Процентиль: 94%
0.13254
Средний

Дефекты

CWE-79