Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh8h-hp63-9c4c

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.

EPSS

Процентиль: 53%
0.00296
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 8 лет назад

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.

CVSS3: 5.4
debian
больше 8 лет назад

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10 ...

EPSS

Процентиль: 53%
0.00296
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79