Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcqm-6ff4-53qx

Опубликовано: 14 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Cross-site Scripting in Strapi

Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

Пакеты

Наименование

strapi

npm
Затронутые версииВерсия исправления

<= 3.6.10

Отсутствует

EPSS

Процентиль: 64%
0.00476
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 3 лет назад

Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

EPSS

Процентиль: 64%
0.00476
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79