Описание
A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:aatifaneeq:voovi:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00185
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.5
github
около 2 лет назад
A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.
EPSS
Процентиль: 40%
0.00185
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79