Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v739-645c-vfcr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

EPSS

Процентиль: 38%
0.00168
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

EPSS

Процентиль: 38%
0.00168
Низкий

Дефекты

CWE-79