Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2xg-gxf7-x426

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 9

Описание

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.

EPSS

Процентиль: 27%
0.00094
Низкий

8.5 High

CVSS4

9 Critical

CVSS3

Дефекты

CWE-97

Связанные уязвимости

CVSS3: 9
nvd
9 месяцев назад

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.

EPSS

Процентиль: 27%
0.00094
Низкий

8.5 High

CVSS4

9 Critical

CVSS3

Дефекты

CWE-97