Описание
Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6 (включая) до 6.5.1 (исключая)Версия от 7 (включая) до 7.2.3 (исключая)
Одно из
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00104
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
около 1 года назад
Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.
EPSS
Процентиль: 29%
0.00104
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79