Описание
YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious attacker can inject JavaScript without any authentication via a form title that is saved in the backend database. When any user visits that injected page, the JavaScript payload gets executed. This issue has been patched in version 4.6.0.
Ссылки
- ProductRelease Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.6.0 (исключая)
cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00213
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
EPSS
Процентиль: 12%
0.00213
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79