Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p48c-42m5-8gmw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.

Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.

EPSS

Процентиль: 50%
0.00268
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.

EPSS

Процентиль: 50%
0.00268
Низкий

Дефекты

CWE-79