Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqr2-347w-52hc

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8

Описание

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

EPSS

Процентиль: 15%
0.00049
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
9 месяцев назад

Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.   Version 5.20 of MegaBIP fixes this issue.

EPSS

Процентиль: 15%
0.00049
Низкий

4.8 Medium

CVSS4

Дефекты

CWE-79