Описание
Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.
Ссылки
- Third Party Advisory
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:nopcommerce:nopcommerce:4.70.1:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01146
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 1 года назад
Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.
EPSS
Процентиль: 78%
0.01146
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79