Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcjj-7w9p-r3m9

Опубликовано: 24 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

EPSS

Процентиль: 24%
0.00083
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

EPSS

Процентиль: 24%
0.00083
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79