ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 15 Π°ΠΏΡ. 2025
ΠΡΡΠΎΡΠ½ΠΈΠΊ: nvd
CVSS3: 4.8
EPSS ΠΠΈΠ·ΠΊΠΈΠΉ
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
Π‘ΡΡΠ»ΠΊΠΈ
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Π£ΡΠ·Π²ΠΈΠΌΡΠ΅ ΠΊΠΎΠ½ΡΠΈΠ³ΡΡΠ°ΡΠΈΠΈ
ΠΠΎΠ½ΡΠΈΠ³ΡΡΠ°ΡΠΈΡ 1
cpe:2.3:a:perfree:perfreeblog:4.0.11:*:*:*:*:*:*:*
EPSS
ΠΡΠΎΡΠ΅Π½ΡΠΈΠ»Ρ: 19%
0.00267
ΠΠΈΠ·ΠΊΠΈΠΉ
4.8 Medium
CVSS3
ΠΠ΅ΡΠ΅ΠΊΡΡ
CWE-79
Π‘Π²ΡΠ·Π°Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ
CVSS3: 4.8
github
Π±ΠΎΠ»ΡΡΠ΅ 1 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
EPSS
ΠΡΠΎΡΠ΅Π½ΡΠΈΠ»Ρ: 19%
0.00267
ΠΠΈΠ·ΠΊΠΈΠΉ
4.8 Medium
CVSS3
ΠΠ΅ΡΠ΅ΠΊΡΡ
CWE-79