Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v66f-9xx4-8g7q

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.

In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.

EPSS

Процентиль: 37%
0.00159
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 7 лет назад

In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.

EPSS

Процентиль: 37%
0.00159
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79