Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p49c-fw45-c97v

Опубликовано: 30 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.

A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.

EPSS

Процентиль: 40%
0.00185
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.

EPSS

Процентиль: 40%
0.00185
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79