Описание
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.
Ссылки
- Permissions Required
- Permissions Required
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cherrytree_project:cherrytree:0.99.30:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00369
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 3 лет назад
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.
CVSS3: 6.1
debian
больше 3 лет назад
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allo ...
CVSS3: 6.1
github
больше 3 лет назад
A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.
EPSS
Процентиль: 58%
0.00369
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79