Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfw8-xm28-h6fx

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 7.2

Описание

Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.

Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.

EPSS

Процентиль: 25%
0.00089
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
nvd
22 дня назад

Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads in custom widget titles and files. Attackers can craft malicious files with embedded scripts that execute when victims interact with the application, potentially enabling remote code execution.

EPSS

Процентиль: 25%
0.00089
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79