Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-47783

Опубликовано: 16 янв. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

EPSS

Процентиль: 7%
0.00028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 5.4
github
23 дня назад

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

EPSS

Процентиль: 7%
0.00028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-434