Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3vw-pmcf-8h54

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additionally access and manipulate customer’s information.

Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additionally access and manipulate customer’s information.

EPSS

Процентиль: 48%
0.00254
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
nvd
почти 5 лет назад

Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additionally access and manipulate customer’s information.

EPSS

Процентиль: 48%
0.00254
Низкий

Дефекты

CWE-79