Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9qw-fh38-x37f

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

OpenCart Cross-site Scripting

OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a massive issue as you are still required to be logged into the admin."

Пакеты

Наименование

opencart/opencart

composer
Затронутые версииВерсия исправления

<= 3.0.3.3

Отсутствует

EPSS

Процентиль: 48%
0.00252
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 5 лет назад

OpenCart 3.0.3.3 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section because of a lack of entity encoding. NOTE: this issue exists because of an incomplete fix for CVE-2020-10596. The vendor states "this is not a massive issue as you are still required to be logged into the admin.

EPSS

Процентиль: 48%
0.00252
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79