Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v57p-q7g2-4g2r

Опубликовано: 22 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

EPSS

Процентиль: 30%
0.00113
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

EPSS

Процентиль: 30%
0.00113
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80