Описание
Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.7.2 (исключая)
cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00143
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 4.8
github
около 3 лет назад
baserCMS vulnerable to stored Cross-site Scripting
EPSS
Процентиль: 35%
0.00143
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
CWE-79