Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcjj-8gfr-rpqw

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.

An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.

EPSS

Процентиль: 18%
0.00058
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
больше 7 лет назад

An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.

EPSS

Процентиль: 18%
0.00058
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79