Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-9441

Опубликовано: 05 июн. 2017
Источник: nvd
CVSS3: 5.4
CVSS3: 2.7
CVSS2: 3.5
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bigtreecms:bigtree_cms:*:*:*:*:*:*:*:*
Версия до 4.2.18 (включая)

EPSS

Процентиль: 40%
0.00185
Низкий

5.4 Medium

CVSS3

2.7 Low

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files."

EPSS

Процентиль: 40%
0.00185
Низкий

5.4 Medium

CVSS3

2.7 Low

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79