Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpx6-gj3w-h6qv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

EPSS

Процентиль: 79%
0.01237
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 4 лет назад

In XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and save an XSS payload in the body of the HTML document. This payload will execute globally on the client side.

EPSS

Процентиль: 79%
0.01237
Низкий

Дефекты

CWE-79