Описание
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
Ссылки
- Issue TrackingThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party AdvisoryVDB Entry
- ExploitIssue TrackingPatchThird Party AdvisoryVDB Entry
- Issue TrackingThird Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party AdvisoryVDB Entry
- ExploitIssue TrackingPatchThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.0 (исключая)
cpe:2.3:a:keystonejs:keystone:*:beta7:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03604
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
EPSS
Процентиль: 87%
0.03604
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79