Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmhh-453x-wvw9

Опубликовано: 26 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.

Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.

EPSS

Процентиль: 57%
0.00356
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.

EPSS

Процентиль: 57%
0.00356
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79