Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9ph-84w3-989x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

EPSS

Процентиль: 91%
0.06088
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
больше 9 лет назад

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

EPSS

Процентиль: 91%
0.06088
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79