Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rj3h-j446-4cfq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.

Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.

EPSS

Процентиль: 63%
0.00456
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax remotely, and further perform reflective XSS attacks.

EPSS

Процентиль: 63%
0.00456
Низкий

Дефекты

CWE-79