Описание
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.
Ссылки
- Product
- Third Party Advisory
- Third Party Advisory
- Product
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.5 (включая) до 1.7.10 (включая)
cpe:2.3:a:yourls:yourls:*:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00561
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
EPSS
Процентиль: 68%
0.00561
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79