Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000887

Опубликовано: 28 дек. 2018
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:peel:peel_shopping:9.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00366
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.

EPSS

Процентиль: 58%
0.00366
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79