Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mr42-h3r5-v8g5

Опубликовано: 30 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a request using the 'nombreApellidos', 'dirección ', and 'comentarios ' parameters to '/processContact.do'.

HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a request using the 'nombreApellidos', 'dirección ', and 'comentarios ' parameters to '/processContact.do'.

EPSS

Процентиль: 27%
0.00345
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
около 1 месяца назад

HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a request using the 'nombreApellidos', 'dirección ', and 'comentarios ' parameters to '/processContact.do'.

EPSS

Процентиль: 27%
0.00345
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79