Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-7149

Опубликовано: 29 дек. 2023
Источник: nvd
CVSS3: 3.5
CVSS3: 6.1
CVSS2: 4
EPSS Низкий

Описание

A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input "> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249153 was assigned to this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:code-projects:qr_code_generator:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00128
Низкий

3.5 Low

CVSS3

6.1 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
github
около 2 лет назад

A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input "><iMg src=N onerror=alert(document.domain)> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249153 was assigned to this vulnerability.

CVSS3: 6.1
fstec
около 2 лет назад

Уязвимость файла /download.php?file=author.png генератора QR-кодов QR Code Generator, позволяющая нарушителю провести атаку межсайтового скриптинга

EPSS

Процентиль: 33%
0.00128
Низкий

3.5 Low

CVSS3

6.1 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79