Описание
A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via
signup2.php in the emailadd parameter, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:aatifaneeq:voovi:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00277
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.5
github
около 2 лет назад
A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via signup2.php in the emailadd parameter, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the browser session of an authenticated user.
EPSS
Процентиль: 51%
0.00277
Низкий
6.5 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79