Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwm7-v4rv-ggff

Опубликовано: 29 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Mealie 3.0.1 and earlier is vulnerable to Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

Mealie 3.0.1 and earlier is vulnerable to Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

EPSS

Процентиль: 21%
0.0007
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9
nvd
4 месяца назад

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

EPSS

Процентиль: 21%
0.0007
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79