Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfvx-jv6h-rrrw

Опубликовано: 08 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

EPSS

Процентиль: 37%
0.0016
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
5 месяцев назад

Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

EPSS

Процентиль: 37%
0.0016
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79