Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc29-mvwv-wpcq

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Cross-site scripting (XSS) vulnerability in CakePHP

Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.

Пакеты

Наименование

cakephp/cakephp

composer
Затронутые версииВерсия исправления

>= 1.0.1.2708, <= 1.1.6.3264

1.1.7.3363

EPSS

Процентиль: 60%
0.00427
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 19 лет назад

Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.

debian
больше 19 лет назад

Cross-site scripting (XSS) vulnerability in cake/libs/error.php in Cak ...

EPSS

Процентиль: 60%
0.00427
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79