Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-40289

Опубликовано: 31 окт. 2022
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phppointofsale:php_point_of_sale:19.0:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00988
Низкий

9 Critical

CVSS3

Дефекты

CWE-79
CWE-79
CWE-79

Связанные уязвимости

CVSS3: 9
github
больше 3 лет назад

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.

EPSS

Процентиль: 76%
0.00988
Низкий

9 Critical

CVSS3

Дефекты

CWE-79
CWE-79
CWE-79