Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-47716

Опубликовано: 23 дек. 2025
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:orangescrum:orangescrum:1.8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 9%
0.00033
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 2 месяцев назад

Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.

EPSS

Процентиль: 9%
0.00033
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79