Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53906

Опубликовано: 17 дек. 2025
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:projectsend:projectsend:r1605:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00026
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
github
около 2 месяцев назад

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

EPSS

Процентиль: 7%
0.00026
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79