Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm2g-3w9w-jr6p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.

An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.

EPSS

Процентиль: 51%
0.00281
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
почти 6 лет назад

An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.

EPSS

Процентиль: 51%
0.00281
Низкий