Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpgq-6jmr-6c67

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

Cross-site Scripting in express-cart

The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website."

EPSS

Процентиль: 44%
0.00212
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 4 лет назад

The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.

EPSS

Процентиль: 44%
0.00212
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79