Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7gr-rcg6-hxhr

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

EPSS

Процентиль: 46%
0.00235
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
почти 4 года назад

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

EPSS

Процентиль: 46%
0.00235
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79