Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m98h-4pjr-7pxh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.

Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.

EPSS

Процентиль: 76%
0.0094
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
около 5 лет назад

Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS) vulnerability.

EPSS

Процентиль: 76%
0.0094
Низкий

Дефекты

CWE-79