Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5m2-r7pq-fxr5

Опубликовано: 10 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8

Описание

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.

EPSS

Процентиль: 22%
0.0007
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
4 месяца назад

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.

EPSS

Процентиль: 22%
0.0007
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79