Описание
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
Ссылки
- Product
- Product
- Broken Link
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:simplemachines:simple_machines_forum:2.1.6:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00079
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 6.1
github
около 2 месяцев назад
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
EPSS
Процентиль: 24%
0.00079
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-20