Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwvf-5fwq-9mq9

Опубликовано: 04 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8

Описание

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.

EPSS

Процентиль: 5%
0.0002
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
5 месяцев назад

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.

EPSS

Процентиль: 5%
0.0002
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79