Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p55v-v434-pf8j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the fileIds parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.

_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the fileIds parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.

EPSS

Процентиль: 55%
0.00328
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
около 6 лет назад

_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the fileIds parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.

EPSS

Процентиль: 55%
0.00328
Низкий