Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqr2-347w-52hc

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8

Описание

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

EPSS

Процентиль: 54%
0.00303
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
11 месяцев назад

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

EPSS

Процентиль: 54%
0.00303
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79