Описание
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
Ссылки
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.3.19 (исключая)
cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00243
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-829
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
EPSS
Процентиль: 47%
0.00243
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-829