Описание
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:huaju:easytest_online_learning_test_platform:1705:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00148
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
EPSS
Процентиль: 36%
0.00148
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79