Описание
jcore/portal/ajaxPortal.jsp in Jalios JCMS 10.0.2 build-20200224104759 allows XSS via the types parameter. Note: It is asserted that this vulnerability is not present in the standard installation of Jalios JCMS
Ссылки
- Not Applicable
- ExploitThird Party Advisory
- Not ApplicableThird Party Advisory
- Vendor Advisory
- Not Applicable
- ExploitThird Party Advisory
- Not ApplicableThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:jalios:jcms:10.0.2:build-20200224104759:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.0044
Низкий
5.3 Medium
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
jcore/portal/ajaxPortal.jsp in Jalios JCMS 10.0.2 build-20200224104759 allows XSS via the types parameter.
EPSS
Процентиль: 63%
0.0044
Низкий
5.3 Medium
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79